Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISK
open
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISK
open
ReferênciaVexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISK
open
ReferênciaVexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
CVE-2009-0650doswindows
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo
28RISK
open
ReferênciaVexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
CVE-2007-1771webappsphp
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RISK
open
ReferênciaVexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
CVE-2008-3257remotewindows
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RISK
open
ReferênciaVexDay Proof
Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)
CVE-2009-0658doswindows
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISK
open
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0672webappsphp
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Morovia Barcode ActiveX Professional 3.3.1304 - Arbitrary File Overwrite
CVE-2007-2644remotewindows
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrar
23RISK
open
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3937webappsasp
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
eCentrex VOIP Client module - 'uacomx.ocx 2.0.1' Remote Buffer Overflow
CVE-2007-4489remotewindows
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote
23RISK
open
ReferênciaVexDay Proof
dotCMS 1.6 - 'id' Local File Inclusion
CVE-2008-3708webappsphp
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
Advanced Electron Forum 1.0.6 - Remote Code Execution
CVE-2008-5090webappsphp
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code em
23RISK
open
ReferênciaVexDay Proof
Sejoong Namo ActiveSquare 6 - 'NamoInstaller.dll' ActiveX Buffer Overflow
CVE-2008-0634remotewindows
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo
23RISK
open
ReferênciaVexDay Proof
Maian Recipe 1.2 - Insecure Cookie Handling
CVE-2008-3322webappsphp
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
CVE-2008-6080webappsphp
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISK
open
ReferênciaVexDay Proof
GC Auction Platinum - 'cate_id' SQL Injection
CVE-2008-3413webappsphp
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Ads Pro - 'dhtml.pl' Remote Command Execution
CVE-2008-6826webappscgi
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par
23RISK
open
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1838webappsphp
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RISK
open
ReferênciaVexDay Proof
WFTPD Pro Server 3.23.1.1 - 'APPE' Remote Buffer Overflow (PoC)
CVE-2006-5826doswindows
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitr
28RISK
open
ReferênciaVexDay Proof
meBiblio 0.4.5 - 'action' Remote File Inclusion
CVE-2007-6089webappsphp
PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mosDirectory 2.3.2 - 'catid' SQL Injection
CVE-2008-0690webappsphp
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote a
23RISK
open
ReferênciaVexDay Proof
PHPX 3.5.16 - Cookie Poisoning / Authentication Bypass
CVE-2008-3489webappsphp
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
iLife iPhoto Photocast - XML Title Remote Format String (PoC)
CVE-2007-0051dososx
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted at
23RISK
open
ReferênciaVexDay Proof
HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service
CVE-2009-0714doswindows
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express
35RISK
open
ReferênciaVexDay Proof
Free Arcade Script 1.0 - Local File Inclusion Command Execution
CVE-2009-0731webappsphp
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and exe
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.