Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1778webappsphp
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RISK
open
ReferênciaVexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RISK
open
ReferênciaVexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
CVE-2007-1394webappsphp
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
CVE-2007-4737webappsphp
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RISK
open
ReferênciaVexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4378webappsphp
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RISK
open
Referência
CVE-2008-4378
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RISK
open
Referência
CVE-2008-5904
The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to h
23RISK
open
Referência
CVE-2014-5115
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RISK
open
Referência
CVE-2008-5923
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5875webappsphp
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISK
open
ReferênciaVexDay Proof
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
CVE-2008-5877webappsphp
Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc
23RISK
open
Referência
CVE-2009-4522
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2008-5881webappsphp
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RISK
open
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5918webappsphp
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier
23RISK
open
ReferênciaVexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
CVE-2006-1540doswindows
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RISK
open
ReferênciaVexDay Proof
ASP-DEV Internal E-Mail System - Authentication Bypass
CVE-2008-5926webappsasp
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
CVE-2006-1542locallinux
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RISK
open
ReferênciaVexDay Proof
FlexPHPNews 0.0.6 / PRO - Authentication Bypass
CVE-2008-5927webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
isweb CMS 3.0 - SQL Injection / Cross-Site Scripting
CVE-2008-5934webappsphp
SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2012-2591
Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attack
23RISK
open
Referência
CVE-2012-2601
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2012-2614
Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d
23RISK
open
Referência
CVE-2012-2740
SQL injection vulnerability in public_html/lists/admin in phpList before 2.10.18 allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2014-5246
The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication
28RISK
open
Referência
CVE-2014-5258
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated
43RISK
open
Referência
CVE-2014-5275
Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote au
23RISK
open
Referência
CVE-2014-5345
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al
23RISK
open
Referência
CVE-2014-5347
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress
23RISK
open
previouspage 559 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.