Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
FretsWeb 1.2 - 'name' Blind SQL Injection
CVE-2009-2113webappsphp
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
CVE-2008-2892webappsphp
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
CVE-2008-7154webappsphp
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/cla
23RISK
open
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2116webappsphp
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to r
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
CVE-2006-6599webappsphp
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RISK
open
ReferênciaVexDay Proof
AJ HYIP ACME - 'news.php' SQL Injection
CVE-2008-2893webappsphp
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
CVE-2007-6184webappsphp
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RISK
open
ReferênciaVexDay Proof
Mega File Hosting Script 1.2 - 'url' Remote File Inclusion
CVE-2009-0966webappsphp
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Prozilla Topsites 1.0 - Arbitrary Edit/Add Users
CVE-2008-1784webappsphp
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2
23RISK
open
ReferênciaVexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
CVE-2006-6755webappsphp
Ixprim 1.2 allows remote attackers to obtain sensitive information via a direct request for kernel/plugins/fckeditor2/ix
23RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2682webappsphp
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pag
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6499webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninsta
23RISK
open
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2864webappsphp
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct req
23RISK
open
ReferênciaVexDay Proof
All Club CMS 0.0.2 - Remote Database Configuration Retrieve
CVE-2008-7069webappsphp
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control,
23RISK
open
ReferênciaVexDay Proof
TinyWebGallery 1.7.6 - Local File Inclusion / Remote Code Execution
CVE-2009-1911webappsphp
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as
23RISK
open
ReferênciaVexDay Proof
Gobbl CMS 1.0 - Insecure Cookie Handling
CVE-2008-5880webappsphp
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setti
23RISK
open
ReferênciaVexDay Proof
ASPPortal 3.2.5 - Database Disclosure
CVE-2008-6382webappsasp
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
CVE-2006-5597remotewindows
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RISK
open
ReferênciaVexDay Proof
SH-News 3.0 - Insecure Cookie Handling
CVE-2008-6664webappsphp
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RISK
open
ReferênciaVexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
CVE-2007-1932webappsphp
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
CVE-2007-2942webappsphp
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
CVE-2008-6863webappsphp
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RISK
open
ReferênciaVexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
CVE-2007-3403webappsphp
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RISK
open
ReferênciaVexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
CVE-2007-4053webappsphp
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2841webappsphp
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
CVE-2008-2902webappsphp
SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Phaos 0.9.2 - 'basename()' Remote Command Execution
CVE-2006-4420webappsphp
Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local
23RISK
open
ReferênciaVexDay Proof
PHP Crawler 0.8 - Remote File Inclusion
CVE-2008-4137webappsphp
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
NuralStorm Webmail 0.98b - 'process.php' Remote File Inclusion
CVE-2006-5386webappsphp
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.