Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
BusinessSpace 1.2 - 'id' SQL Injection
CVE-2009-0516webappsphp
SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
My Game Script 2.0 - Authentication Bypass
CVE-2009-1816webappsphp
SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
iG Shop 1.4 - 'page.php' SQL Injection
CVE-2007-2717webappsphp
SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld URL Rotator - SQL Injection
CVE-2008-3750webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
GetMyOwnArcade - 'search.php?query' SQL Injection
CVE-2007-4386webappsphp
SQL injection vulnerability in search.php in GetMyOwnArcade allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Kasseler CMS 1.1.0/1.2.0 Lite - SQL Injection
CVE-2008-4356webappsphp
Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
ZEEMATRI 3.0 - 'adid' SQL Injection
CVE-2008-5782webappsphp
SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
CVE-2007-6127webappsphp
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
DWdirectory 2.1 - SQL Injection
CVE-2007-6392webappsphp
SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
taifajobs 1.0 - 'jobid' SQL Injection
CVE-2009-0727webappsphp
SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
FaScript FaMp3 1.0 - SQL Injection
CVE-2008-0327webappsphp
SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2009-1316webappsphp
Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Bible Study 1.5.0 - 'id' SQL Injection
CVE-2008-2643webappsphp
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
Mybizz-Classifieds - 'cat' SQL Injection
CVE-2008-2845webappsphp
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Webdevindo-CMS 0.1 - 'hal' SQL Injection
CVE-2008-2875webappsphp
SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
geccBBlite 2.0 - 'id' SQL Injection
CVE-2008-4517webappsphp
SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
myEvent 1.6 - 'eventdate' SQL Injection
CVE-2008-4650webappsphp
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Aj RSS Reader - 'url' SQL Injection
CVE-2008-4753webappsphp
SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Mambo Component mambads 1.0 RC1 Beta - SQL Injection
CVE-2008-5226webappsphp
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote atta
23RISK
open
ReferênciaVexDay Proof
SHOP-INET 4 - 'grid' SQL Injection
CVE-2009-0292webappsphp
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Script Toko Online 5.01 - SQL Injection
CVE-2009-0296webappsphp
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_waticketsystem - Blind SQL Injection
CVE-2009-0333webappsphp
SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
EasyWay CMS - 'mid' SQL Injection
CVE-2008-2555webappsphp
SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
GLLCTS2 < 4.2.4 - 'detail' SQL Injection
CVE-2008-2746webappsphp
SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
CVE-2007-4581webappsphp
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.1 - 'table' SQL Injection
CVE-2007-5719webappsphp
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
HoMaP-CMS 0.1 - 'go' SQL Injection
CVE-2008-2989webappsphp
SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
MMSLamp - 'idpro' SQL Injection
CVE-2007-6575webappsphp
SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
pLink 2.07 - 'linkto.php' Blind SQL Injection
CVE-2008-4357webappsphp
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.