Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Social Site Generator 2.0 - 'path' Remote File Inclusion
CVE-2008-6421webappsphp
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attacke
23RISK
open
ReferênciaVexDay Proof
2532/Gigs 1.2.1 - 'activateuser.php' Local File Inclusion
CVE-2007-4585webappsphp
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
Pollbooth 2.0 - 'pollID' SQL Injection
CVE-2008-4765webappsphp
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
CyberBrau 0.9.4 - '/forum/track.php' Remote File Inclusion
CVE-2006-5400webappsphp
PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows
23RISK
open
ReferênciaVexDay Proof
MyCMS 0.9.8 - Remote Command Execution (1)
CVE-2007-3587webappsphp
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a
23RISK
open
ReferênciaVexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
CVE-2007-5452webappsphp
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
xeCMS 1.x - 'view.php' Remote File Disclosure
CVE-2007-6508webappsphp
Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (
23RISK
open
ReferênciaVexDay Proof
TlAds 1.0 - Remote Insecure Cookie Handling
CVE-2008-4783webappsphp
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo
23RISK
open
ReferênciaVexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0828webappsphp
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
CVE-2006-0308webappsphp
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RISK
open
ReferênciaVexDay Proof
PortailPHP mod_phpalbum 2.1.5 - 'chemin' Remote File Inclusion
CVE-2006-4498webappsphp
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remo
23RISK
open
ReferênciaVexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
CVE-2009-1050webappsphp
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYou
23RISK
open
ReferênciaVexDay Proof
sBLOG 0.7.3 Beta - '/inc/lang.php' Local File Inclusion
CVE-2007-1801webappsphp
Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arb
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Jobs 2.4 - 'cid' SQL Injection
CVE-2007-2370webappsphp
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
CVE-2007-3633remotewindows
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 al
23RISK
open
ReferênciaVexDay Proof
DevMass Shopping Cart 1.0 - Remote File Inclusion
CVE-2007-6133webappsphp
PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-1906webappsphp
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
CVE-2007-6311webappsphp
SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows rem
23RISK
open
ReferênciaVexDay Proof
aflog 1.01 - Multiple Insecure Cookie Handling Vulnerabilities
CVE-2008-4784webappsphp
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a c
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.mid' Integer Overflow (PoC)
CVE-2009-1331doswindows
Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of ser
28RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer - XML Parsing Remote Buffer Overflow
CVE-2008-4844remotewindows
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISK
open
ReferênciaVexDay Proof
LeadTools Raster Thumbnail Object Library - 'LTRTM14e.dll' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7089webappsphp
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script
23RISK
open
ReferênciaVexDay Proof
SiteDepth CMS 3.44 - 'ShowImage.php?name' File Disclosure
CVE-2007-3404webappsphp
Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin WassUp 1.4.3 - 'to_date' SQL Injection
CVE-2008-0520webappsphp
Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att
23RISK
open
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1663webappsphp
Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4875remotehardware
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and
23RISK
open
ReferênciaVexDay Proof
chCounter 3.1.3 - Authentication Bypass
CVE-2009-1347webappsphp
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Apollo 37zz - '.m3u' Local Heap Overflow (PoC)
CVE-2009-1351doswindows
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and p
23RISK
open
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1368webappsphp
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.