Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
CVE-2006-2576webappsphp
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
CVE-2007-0016localwindows
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RISK
open
ReferênciaVexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
CVE-2007-1766webappsphp
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2431webappsphp
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
CVE-2007-2826webappsphp
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
PHP JOBWEBSITE PRO - 'JobSearch3.php' SQL Injection
CVE-2008-2914webappsphp
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote att
23RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Authentication Bypass
CVE-2009-0459webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remot
23RISK
open
ReferênciaVexDay Proof
Mx Module Smartor Album FAP 2.0 RC 1 - Remote File Inclusion
CVE-2007-2189webappsphp
PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 mod
23RISK
open
ReferênciaVexDay Proof
FlashBB 1.1.8 - 'sendmsg.php' Remote File Inclusion
CVE-2007-3697webappsphp
PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to exe
28RISK
open
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
CVE-2009-0461webappsphp
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RISK
open
ReferênciaVexDay Proof
ClickCart 6.0 - Authentication Bypass
CVE-2009-0462webappsphp
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
CVE-2006-4672webappsphp
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RISK
open
ReferênciaVexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
CVE-2008-2917webappsasp
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
CVE-2006-5551doswindows
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RISK
open
ReferênciaVexDay Proof
phpBLASTER CMS 1.0 RC1 - Multiple Local File Inclusions
CVE-2008-5171webappsphp
Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals
23RISK
open
ReferênciaVexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
CVE-2006-7169webappsphp
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RISK
open
ReferênciaVexDay Proof
KVIrc 3.4.2 Shiny - URI handler Remote Command Execution
CVE-2008-7070remotewindows
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
groone's Guestbook 2.0 - Remote File Inclusion
CVE-2009-0464webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Axiom Photo/News Gallery 0.8.6 - Remote File Inclusion
CVE-2007-0200webappsphp
PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 a
23RISK
open
ReferênciaVexDay Proof
GLLCTS2 - 'sort' Blind SQL Injection
CVE-2008-2919webappsphp
SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0468remotewindows
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RISK
open
ReferênciaVexDay Proof
AgerMenu 0.01 - 'top.inc.php?rootdir' Remote File Inclusion
CVE-2007-0837webappsphp
PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 - '.pls' Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open
ReferênciaVexDay Proof
Extcalendar 2 - 'profile.php' Remote User Pass Change
CVE-2007-0681webappsphp
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without prov
23RISK
open
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 - '.pls' Universal Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISK
open
ReferênciaVexDay Proof
study planner (studiewijzer) 0.15 - Remote File Inclusion
CVE-2007-1628webappsphp
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa
23RISK
open
ReferênciaVexDay Proof
NUNE News Script 2.0pre2 - Multiple Remote File Inclusions
CVE-2007-0143webappsphp
Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
minb 0.1.0 - Remote Code Execution
CVE-2008-7005webappsphp
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
CVE-2007-1118webappsphp
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.