Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
CVE-2008-0612webappsphp
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
CVE-2006-6673doswindows
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open
ReferênciaVexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
CVE-2008-5209webappsphp
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RISK
open
ReferênciaVexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
CVE-2007-0300webappsphp
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ibase 2.03 - Remote File Disclosure
CVE-2008-6288webappsphp
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
CVE-2007-2184webappsphp
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
CVE-2009-1602doswindows
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RISK
open
ReferênciaVexDay Proof
MiniWeb HTTP Server 0.8.x - Remote Denial of Service
CVE-2007-3159doswindows
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negat
23RISK
open
ReferênciaVexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
CVE-2009-1735webappsphp
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RISK
open
ReferênciaVexDay Proof
Picturesolution 2.1 - 'config.php?path' Remote File Inclusion
CVE-2007-5313webappsphp
PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
kontakt formular 1.4 - Remote File Inclusion
CVE-2007-6655webappsphp
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin Download - 'dl_id' SQL Injection
CVE-2008-1646webappsphp
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Simple HTTPd 1.38 - Multiple Vulnerabilities
CVE-2007-6404remotewindows
Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attac
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin WP-Cal 0.3 - 'editevent.php' SQL Injection
CVE-2008-0490webappsphp
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2981webappsphp
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when regist
23RISK
open
ReferênciaVexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6292webappsphp
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RISK
open
ReferênciaVexDay Proof
AvailScript Jobs Portal Script - (Authenticated) Arbitrary File Upload
CVE-2008-7021webappsphp
Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated use
23RISK
open
ReferênciaVexDay Proof
Popcorn 1.87 - Remote Heap Overflow (PoC)
CVE-2009-1647doswindows
Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of serv
23RISK
open
ReferênciaVexDay Proof
Web Oddity Web Server 0.09b - Directory Traversal
CVE-2007-4726remotelinux
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot)
23RISK
open
ReferênciaVexDay Proof
Joomla! Component GameQ 4.0 - SQL Injection
CVE-2008-2701webappsphp
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
e107 0.617 - Cross-Site Scripting Remote Cookie Disclosure
CVE-2005-2327webappsphp
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web scrip
23RISK
open
ReferênciaVexDay Proof
SiteBuilderElite 1.2 - Multiple Remote File Inclusions
CVE-2008-1123webappsphp
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
CVE-2008-2346webappsphp
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creat
23RISK
open
ReferênciaVexDay Proof
Tlnews 2.2 - Insecure Cookie Handling
CVE-2008-4752webappsphp
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login c
23RISK
open
ReferênciaVexDay Proof
Poppawid 2.7 - 'form' Remote File Inclusion
CVE-2007-5221webappsphp
PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6546webappsphp
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a m
23RISK
open
ReferênciaVexDay Proof
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
CVE-2009-2151webappsphp
Directory traversal vulnerability in index.php in AdaptWeb 0.9.2 allows remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2666webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote att
23RISK
open
ReferênciaVexDay Proof
Project Based Calendaring System (PBCS) 0.7.1 - Multiple Vulnerabilities
CVE-2008-2215webappsphp
Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
FreeLyrics 1.0 - Remote File Disclosure
CVE-2008-5861webappsphp
Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via di
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.