Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
RhinoSoft Serv-U FTP Server 7.3 - (Authenticated) 'stou con:1' Denial of Service
CVE-2008-4500doswindows
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consu
28RISK
open
ReferênciaVexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
CVE-2008-6451webappsphp
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Winamp 5.34 - '.mp4' Code Execution
CVE-2007-2498localwindows
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .
28RISK
open
ReferênciaVexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
CVE-2008-6452webappsphp
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Joomla! Component pcchess 0.8 - SQL Injection
CVE-2008-0761webappsphp
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Jooml
23RISK
open
ReferênciaVexDay Proof
Diesel Pay Script - 'area' SQL Injection
CVE-2008-6468webappsphp
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
CVE-2008-6469webappsphp
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
CVE-2007-3370webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open
ReferênciaVexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
CVE-2008-6471webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
CVE-2008-6477webappsphp
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
ReferênciaVexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
CVE-2008-6481webappsphp
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 / Provideo Camimage - 'ISSCamControl.dll 1.0.1.5' Remote Buffer Overflow
CVE-2007-3111remotewindows
Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used
35RISK
open
ReferênciaVexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
CVE-2008-6482webappsphp
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RISK
open
ReferênciaVexDay Proof
Joomla! Component VirtueMart Google Base 1.1 - Remote File Inclusion
CVE-2008-6483webappsphp
PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_go
28RISK
open
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_galeria - SQL Injection
CVE-2008-0833webappsphp
SQL injection vulnerability in index.php in the com_galeria component for Joomla! allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
CVE-2008-0847webappsphp
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
CVE-2008-6488webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
CVE-2008-6490webappsphp
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RISK
open
ReferênciaVexDay Proof
Easy News Content Management - Database Disclosure
CVE-2008-6493webappsasp
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RISK
open
ReferênciaVexDay Proof
ASP User Engine .NET - Remote Database Disclosure
CVE-2008-6494webappsphp
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-6502webappsphp
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local
23RISK
open
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6508webappsjsp
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISK
open
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6511webappsjsp
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RISK
open
ReferênciaVexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
CVE-2007-3400remotewindows
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open
ReferênciaVexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
CVE-2008-6513webappsphp
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
CVE-2007-3401webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISK
open
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1982webappsphp
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6523webappsphp
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.