Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,266 exploits
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3451webappsphp
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to exec
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
CVE-2008-0612webappsphp
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
Web Slider 0.6 - Insecure Cookie/Authentication Handling
CVE-2008-2298webappsphp
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin co
23RISK
open
ReferênciaVexDay Proof
txtSQL 2.2 Final - 'startup.php' Remote File Inclusion
CVE-2008-3595webappsphp
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers
23RISK
open
ReferênciaVexDay Proof
PhpBlock a8.5 - Multiple Remote File Inclusions
CVE-2008-5210webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code
23RISK
open
Referência
CVE-2021-30150
Composr 10.0.36 allows XSS in an XML script.
23RISK
open
Referência
CVE-2022-1631
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
33RISK
open
Referência
CVE-2010-4612
Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote
23RISK
open
ReferênciaVexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
CVE-2008-2691webappsasp
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2022-21371
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RISK
open
Referência
CVE-2010-1267
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RISK
open
Referência
CVE-2010-1267
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RISK
open
Referência
CVE-2009-4698
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute
23RISK
open
Referência
CVE-2009-4698
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
RealPlayer 11 - '.au' Denial of Service
CVE-2007-6235doswindows
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISK
open
ReferênciaVexDay Proof
AGENCY4NET WEBFTP 1 - 'download2.php' File Disclosure
CVE-2008-0091webappsphp
Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arb
23RISK
open
ReferênciaVexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
CVE-2009-1739webappsphp
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RISK
open
Referência
CVE-2009-4700
Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .
23RISK
open
Referência
CVE-2009-0640
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re
23RISK
open
ReferênciaVexDay Proof
IDM-OS 1.0 - 'Filename' File Disclosure
CVE-2008-0431webappsphp
Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to re
23RISK
open
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-3205webappsphp
Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
BbZL.php 0.92 - Insecure Cookie Handling
CVE-2008-4708webappsphp
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admi
23RISK
open
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5576webappsphp
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain adminis
23RISK
open
ReferênciaVexDay Proof
asp-project 1.0 - Insecure Cookie Method
CVE-2009-0280webappsasp
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open
Referência
CVE-2025-34184
Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection
48RISK
open
Referência
CVE-2025-34184
Ilevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection
48RISK
open
Referência
CVE-2018-5720
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C
23RISK
open
Referência
CVE-2009-4808
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
CVE-2006-6673doswindows
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open
Referência
CVE-2012-5243
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v
23RISK
open
previouspage 451 / 743next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.