Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2446webappsphp
Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow rem
23RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
MolyX BOARD 2.5.0 - 'index.php?lang' Local File Inclusion
CVE-2007-2778webappsphp
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - Remote Command Execution
CVE-2009-2111webappsphp
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-2242doswindows
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RISK
open
ReferênciaVexDay Proof
ItCMS 1.9 - 'boxpop.php' Remote Code Execution
CVE-2008-2192webappsphp
Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
CVE-2007-2009webappsphp
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
CVE-2008-4380doshardware
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RISK
open
ReferênciaVexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
CVE-2007-2643webappsphp
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP Jokesite 2.0 - 'cat_id' SQL Injection
CVE-2008-2457webappsphp
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5749remotewindows
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Trionic Cite CMS 1.2rev9 - Remote File Inclusion
CVE-2007-5271webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to ex
28RISK
open
ReferênciaVexDay Proof
Siemens C450IP/C475IP - Remote Denial of Service
CVE-2008-7065doshardware
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and dev
23RISK
open
ReferênciaVexDay Proof
idmos-phoenix CMS - 'aural.php' Remote File Inclusion
CVE-2007-5293webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arb
23RISK
open
ReferênciaVexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
CVE-2009-1067webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web
23RISK
open
ReferênciaVexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
CVE-2008-2483webappsphp
Directory traversal vulnerability in index.php in Xomol CMS 1.20071213 allows remote attackers to include and execute ar
23RISK
open
ReferênciaVexDay Proof
AJ HYIP ACME - 'topic_detail.php' SQL Injection
CVE-2008-2532webappsphp
SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2533webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
openPHPNuke 2.3.3 - Remote File Inclusion
CVE-2006-2137webappsphp
PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Synactis All_IN_THE_BOX ActiveX 3.0 - Null Byte File Overwrite
CVE-2009-0465remotewindows
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX
23RISK
open
ReferênciaVexDay Proof
DynamicPAD 1.02.18 - 'HomeDir' Remote File Inclusion
CVE-2007-2527webappsphp
Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
LunarPoll 1.0 - 'show.php?PollDir' Remote File Inclusion
CVE-2007-0298webappsphp
PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
idmos-phoenix CMS - 'aural.php' Remote File Inclusion
CVE-2007-5294webappsphp
PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
WzdFTPD 0.8.0 - 'USER' Remote Denial of Service
CVE-2007-5300doswindows
Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other ve
23RISK
open
ReferênciaVexDay Proof
Gradman 0.1.3 - 'agregar_info.php' Local File Inclusion
CVE-2008-0361webappsphp
Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
OpenDock Easy Blog 1.4 - 'doc_directory' File Inclusion
CVE-2006-5244webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RISK
open
ReferênciaVexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-1908webappsphp
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
PHP Visit Counter 0.4 - 'datespan' SQL Injection
CVE-2008-2556webappsphp
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
AlsaPlayer < 0.99.80-rc3 - Vorbis Input Local Buffer Overflow
CVE-2007-5301locallinux
Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in Alsa
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.