Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2022webappsasp
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
Minerva 2.0.21 build 238a - 'phpbb_root_path' File Inclusion
CVE-2006-5077webappsphp
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and ear
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JooBB 0.5.9 - Blind SQL Injection
CVE-2008-2651webappsphp
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows r
23RISK
open
ReferênciaVexDay Proof
LightNEasy sqlite / no database 1.2.2 - Multiple Vulnerabilities
CVE-2008-6593webappsphp
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
MemHT Portal 4.0.1 - Remote Code Execution
CVE-2009-0372webappsphp
Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
Company WebSite Builder PRO 1.9.8 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1513webappsphp
PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_g
23RISK
open
ReferênciaVexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
CVE-2007-2660webappsphp
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, a
23RISK
open
ReferênciaVexDay Proof
Telephone Directory 2008 - SQL Injection / Cross-Site Scripting
CVE-2008-2678webappsphp
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote atta
23RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2679webappsphp
SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allo
23RISK
open
ReferênciaVexDay Proof
BandSite CMS 1.1.4 - Insecure Cookie Handling
CVE-2008-5497webappsphp
BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_
23RISK
open
ReferênciaVexDay Proof
SyntaxCMS 1.3 - '0004_init_urls.php' Remote File Inclusion
CVE-2006-5055webappsphp
PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows
23RISK
open
ReferênciaVexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
CVE-2008-0338remotewindows
Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remo
23RISK
open
ReferênciaVexDay Proof
Siteman 1.1.9 - 'cat' Remote File Disclosure
CVE-2008-0452webappsphp
Directory traversal vulnerability in articles.php in Siteman 1.1.9 allows remote attackers to read arbitrary files via d
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BIDIB.ocx' Multiple Vulnerabilities
CVE-2008-2683remotewindows
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RISK
open
ReferênciaVexDay Proof
Aj Classifieds - Authentication Bypass
CVE-2008-7041webappsphp
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request t
23RISK
open
ReferênciaVexDay Proof
ilchClan 1.05g - 'tid' SQL Injection
CVE-2006-0851webappsphp
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Web Slider 0.6 - Insecure Cookie/Authentication Handling
CVE-2008-2298webappsphp
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin co
23RISK
open
ReferênciaVexDay Proof
txtSQL 2.2 Final - 'startup.php' Remote File Inclusion
CVE-2008-3595webappsphp
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Site-Assistant 0990 - 'paths[version]' Remote File Inclusion
CVE-2007-0867webappsphp
PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
PhpBlock a8.5 - Multiple Remote File Inclusions
CVE-2008-5210webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
CyBoards PHP Lite 1.21 - 'script_path' Remote File Inclusion
CVE-2007-1983webappsphp
PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Sisplet CMS 05.10 - 'site_path' Remote File Inclusion
CVE-2007-2347webappsphp
PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier a
23RISK
open
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3451webappsphp
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to exec
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
CVE-2008-0612webappsphp
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
CVE-2006-6673doswindows
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open
ReferênciaVexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
CVE-2008-5209webappsphp
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RISK
open
ReferênciaVexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
CVE-2007-0300webappsphp
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ibase 2.03 - Remote File Disclosure
CVE-2008-6288webappsphp
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
CVE-2007-2184webappsphp
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
CVE-2009-1602doswindows
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.