Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
PHP-Nuke Downloads Module - 'sid' SQL Injection
CVE-2004-2000webappsphp21 Feb 2008
SQL injection vulnerability in the Downloads module in Php-Nuke 6.x through 7.2 allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
XOOPS 'prayerlist' Module - 'cid' SQL Injection
CVE-2008-0936webappsphp21 Feb 2008
SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Eagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'ClassList.asp?Term' SQL Injection
CVE-2008-0943webappsphp21 Feb 2008
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Eagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'Labels.asp?Term' SQL Injection
CVE-2008-0943webappsasp21 Feb 2008
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Eagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'Comments.asp?FC' SQL Injection
CVE-2008-0943webappsasp21 Feb 2008
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers t
23RISK
open
Exploit-DBVexDay Proof
XOOPS Tiny Event 1.01 - 'print' Option SQL Injection
CVE-2008-0937webappsphp21 Feb 2008
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Eagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'GradebookStuScores.asp?GrdBk' SQL Injection
CVE-2008-0942webappsphp21 Feb 2008
SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows re
23RISK
open
Exploit-DBVexDay Proof
Sybase MobiLink 10.0.1.3629 - Multiple Heap Buffer Overflow Vulnerabilities
CVE-2008-0912dosmultiple20 Feb 2008
Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere
28RISK
open
Exploit-DBVexDay Proof
SIMM-Comm SCI Photo Chat 3.4.9 - Directory Traversal
CVE-2008-1169remotewindows19 Feb 2008
Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote a
23RISK
open
Exploit-DBVexDay Proof
Google Hack Honeypot File Upload Manager 1.3 - 'delall' Unauthorized File Access
CVE-2008-5283webappsphp19 Feb 2008
Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors
23RISK
open
Exploit-DBVexDay Proof
SmarterTools SmarterMail 4.3 - 'Subject' HTML Injection
CVE-2008-0872webappsphp19 Feb 2008
Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
Joomla! / Mambo Component com_profile - 'oid' SQL Injection
CVE-2008-0846webappsphp19 Feb 2008
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
Facile Forms 1.x - 'catid' SQL Injection
CVE-2008-0855webappsphp19 Feb 2008
SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
Jinzora 2.7.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0877webappsphp19 Feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke Web_Links Module - 'cid' SQL Injection
CVE-2008-0879webappsphp19 Feb 2008
SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Jinzora 2.7.5 - 'slim.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0877webappsphp19 Feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Jinzora 2.7.5 - 'popup.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0877webappsphp19 Feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Jinzora 2.7.5 - 'ajax_request.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0877webappsphp19 Feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
WebcamXP 3.72.440/4.05.280 Beta - '/show_gallery_pic?id' Arbitrary Memory Disclosure
CVE-2008-5674webappsmultiple18 Feb 2008
Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0918webappsphp18 Feb 2008
SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Jo
23RISK
open
Exploit-DBVexDay Proof
Joomla! / Mambo Component com_detail - 'id' SQL Injection
CVE-2008-0853webappsphp18 Feb 2008
SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin wp-people 2.0 - 'wp-people-popup.php' SQL Injection
CVE-2008-0845webappsphp18 Feb 2008
SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote atta
23RISK
open
Exploit-DBVexDay Proof
RunCMS 1.6.1 - 'admin.php' Cross-Site Scripting
CVE-2008-7222webappsphp18 Feb 2008
Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
ProjectPier 0.8 - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities
CVE-2008-5584webappsphp18 Feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
WebcamXP 3.72.440/4.05.280 Beta - '/pocketpc?camnum' Arbitrary Memory Disclosure
CVE-2008-5674webappsmultiple18 Feb 2008
Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and
23RISK
open
Exploit-DBVexDay Proof
Yellow Swordfish Simple Forum 1.x - 'sf-profile.php' SQL Injection
CVE-2008-7040webappsphp18 Feb 2008
SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remo
23RISK
open
Exploit-DBVexDay Proof
freeSSHd 1.2 - 'SSH2_MSG_NEWKEYS' Remote Denial of Service
CVE-2008-0852doslinux17 Feb 2008
freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to T
23RISK
open
Exploit-DBVexDay Proof
Foxit WAC Remote Access Server 2.0 Build 3503 - Heap Buffer Overflow
CVE-2008-7031dosmultiple16 Feb 2008
Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to caus
23RISK
open
Exploit-DBVexDay Proof
Power Phlogger 2.2.x - Cross-Site Scripting
CVE-2009-4253webappsphp16 Feb 2008
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitr
23RISK
open
Exploit-DBVexDay Proof
Joomla! / Mambo Component Filebase - 'filecatid' SQL Injection
CVE-2008-0817webappsphp16 Feb 2008
SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbit
23RISK
open
previouspage 497 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.