Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
CVE-2007-3683webappsphp
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0337webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
S-Gastebuch 1.5.3 - 'gb_pfad' Remote File Inclusion
CVE-2007-1011webappsphp
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
CVE-2008-0337remotewindows
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RISK
open
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2535webappsphp
Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
CVE-2009-0350doswindows
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RISK
open
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Mail Machine 3.989 - Local File Inclusion
CVE-2007-3702webappsphp
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RISK
open
ReferênciaVexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
CVE-2008-1501dosmultiple
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RISK
open
ReferênciaVexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
CVE-2008-2569webappsphp
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
CVE-2009-0369remotewindows
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RISK
open
ReferênciaVexDay Proof
SiteXS CMS 0.1.1 - Local File Inclusion
CVE-2009-0371webappsphp
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
CVE-2009-0373webappsphp
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla!
23RISK
open
ReferênciaVexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
CVE-2006-6552webappsphp
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
CitectSCADA ODBC Server - Remote Stack Buffer Overflow (Metasploit)
CVE-2008-2639remotewindows
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0986webappsphp
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remot
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
CVE-2009-0381webappsphp
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RISK
open
ReferênciaVexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
CVE-2009-0384webappsphp
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
CVE-2007-3536remotewindows
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open
ReferênciaVexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
CVE-2009-0409webappsphp
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
CVE-2007-3271webappsphp
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
CVE-2008-0422webappsphp
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
CVE-2009-0426webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.