Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,813cataloged exploits
35,788CVEs with public exploitation
24,695lab-tested
22,523 exploits
ReferênciaVexDay Proof
Check New 4.52 - SQL Injection
CVE-2008-5586webappsphp
SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is
23RISK
open
Referência
CVE-2026-57517
Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter
48RISK
open
ReferênciaVexDay Proof
phpPgAdmin 4.2.1 - '_language' Local File Inclusion
CVE-2008-5587webappsphp
Directory traversal vulnerability in libraries/lib.inc.php in phpPgAdmin 4.2.1 and earlier, when register_globals is ena
43RISK
open
ReferênciaVexDay Proof
RankEm - 'siteID' SQL Injection
CVE-2008-5588webappsasp
SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Rankem - Authentication Bypass
CVE-2008-5589webappsasp
SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Product Sale Framework 0.1b - SQL Injection
CVE-2008-5590webappsphp
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RISK
open
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5591webappsphp
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RISK
open
Referência
CVE-2014-5088
Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via
23RISK
open
Referência
CVE-2014-5094
Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.p
23RISK
open
ReferênciaVexDay Proof
webClassifieds 2005 - Authentication Bypass
CVE-2008-5817webappsphp
Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers
23RISK
open
Referência
CVE-2023-22518
CVE-2023-22518CRITICALunder attackransomware
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authoriz
100RISK
open
Referência
CVE-2021-1498
CVE-2021-1498CRITICALunder attack
Cisco HyperFlex HX Command Injection Vulnerabilities
100RISK
open
Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RISK
open
Referência
CVE-2012-2580
Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows re
23RISK
open
Referência
CVE-2012-2583
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers
23RISK
open
Referência
CVE-2012-2584
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitr
23RISK
open
Referência
CVE-2014-5201
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2008-6104
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
Referência
CVE-2008-6132
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RISK
open
Referência
CVE-2008-6132
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RISK
open
ReferênciaVexDay Proof
BMForum 5.6 - 'tagname' SQL Injection
CVE-2008-6091webappsphp
SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
phpscripts Ranking Script - Insecure Cookie Handling
CVE-2008-6092webappsphp
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an
23RISK
open
Referência
CVE-2009-4540
SQL injection vulnerability in page.php in Mini CMS 1.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Noname CMS 1.0 - Multiple SQL Injections
CVE-2008-6093webappsphp
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Discussion Forums 2k 3.3 - Multiple SQL Injections
CVE-2008-6100webappsphp
Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote atta
23RISK
open
ReferênciaVexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
CVE-2008-6118webappsphp
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RISK
open
ReferênciaVexDay Proof
Full PHP Emlak Script - 'arsaprint.php' SQL Injection
CVE-2008-6133webappsphp
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
JW Player - 'playerready' Cross-Site Scripting
CVE-2012-3351webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Flexphpic 0.0.x - Authentication Bypass
CVE-2008-6142webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.
23RISK
open
Referência
CVE-2012-2910
Multiple cross-site scripting (XSS) vulnerabilities in SiliSoftware phpThumb() 1.7.11 allow remote attackers to inject a
23RISK
open
previouspage 593 / 751next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.