Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
CVE-2009-0442webappsphp
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
DreamPics Photo/Video Gallery - Blind SQL Injection
CVE-2009-0445webappsphp
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
CVE-2009-2022webappsasp
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RISK
open
ReferênciaVexDay Proof
Carscripts Classifieds - 'cat' SQL Injection
CVE-2008-2844webappsphp
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Agora 1.4 RC1 - 'MysqlfinderAdmin.php' Remote File Inclusion
CVE-2006-7194webappsphp
PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.AVI' File Denial of Service
CVE-2007-0562doswindows
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause
28RISK
open
ReferênciaVexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
CVE-2008-6920webappsphp
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RISK
open
ReferênciaVexDay Proof
Maian Recipe 1.0 - 'path_to_folder' Remote File Inclusion
CVE-2007-0848webappsphp
PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Realtor 747 - 'index.php?categoryId' SQL Injection
CVE-2007-3810webappsphp
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
CVE-2009-2122webappsphp
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RISK
open
ReferênciaVexDay Proof
eSyndiCat Directory Software - Multiple SQL Injections
CVE-2007-3811webappsphp
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the
23RISK
open
ReferênciaVexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
CVE-2009-0457webappsphp
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
WebChamado 1.1 - Arbitrary Add Admin
CVE-2008-2907webappsphp
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open
ReferênciaVexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
CVE-2006-2576webappsphp
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
CVE-2007-0016localwindows
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RISK
open
ReferênciaVexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
CVE-2007-1766webappsphp
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2431webappsphp
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
CVE-2007-2826webappsphp
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
PHP JOBWEBSITE PRO - 'JobSearch3.php' SQL Injection
CVE-2008-2914webappsphp
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote att
23RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Authentication Bypass
CVE-2009-0459webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remot
23RISK
open
ReferênciaVexDay Proof
Mx Module Smartor Album FAP 2.0 RC 1 - Remote File Inclusion
CVE-2007-2189webappsphp
PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 mod
23RISK
open
ReferênciaVexDay Proof
FlashBB 1.1.8 - 'sendmsg.php' Remote File Inclusion
CVE-2007-3697webappsphp
PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to exe
28RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
CVE-2009-0461webappsphp
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RISK
open
ReferênciaVexDay Proof
ClickCart 6.0 - Authentication Bypass
CVE-2009-0462webappsphp
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
Axiom Photo/News Gallery 0.8.6 - Remote File Inclusion
CVE-2007-0200webappsphp
PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 a
23RISK
open
ReferênciaVexDay Proof
GLLCTS2 - 'sort' Blind SQL Injection
CVE-2008-2919webappsphp
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0468remotewindows
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RISK
open
ReferênciaVexDay Proof
AgerMenu 0.01 - 'top.inc.php?rootdir' Remote File Inclusion
CVE-2007-0837webappsphp
PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 - '.pls' Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.