Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
CVE-2006-6866webappsphp
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
ReferênciaVexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1326doswindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
RM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1326localwindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
CVE-2006-6872webappsphp
Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
Open Azimyt CMS 0.22 - 'lang' Local File Inclusion
CVE-2008-2820webappsphp
Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote
23RISK
open
ReferênciaVexDay Proof
RoseOnlineCMS 3 beta2 - 'op' Local File Inclusion
CVE-2007-1636webappsphp
Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files
23RISK
open
ReferênciaVexDay Proof
Sepcity Classified - 'ID' SQL Injection
CVE-2008-6157webappsasp
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent at
23RISK
open
ReferênciaVexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1327localwindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1118remotewindows
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging informat
23RISK
open
ReferênciaVexDay Proof
CMScout 2.05 - 'bit' Local File Inclusion
CVE-2008-3415webappsphp
Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attacker
23RISK
open
ReferênciaVexDay Proof
openEngine 2.0 beta2 - Remote File Inclusion
CVE-2008-4719webappsphp
PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_gl
23RISK
open
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RISK
open
ReferênciaVexDay Proof
Sendcard 3.4.1 - Local File Inclusion / Remote Code Execution
CVE-2007-3082webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and e
23RISK
open
ReferênciaVexDay Proof
Grestul 1.2 - Remote Add Administrator Account
CVE-2009-2040webappsphp
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authenticati
23RISK
open
ReferênciaVexDay Proof
Newswriter SW 1.42 - 'editfunc.inc.php' File Inclusion
CVE-2006-5102webappsphp
PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter S
23RISK
open
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1400remotewindows
Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earl
23RISK
open
ReferênciaVexDay Proof
Eudora 7.1 - SMTP ResponseRemote Remote Buffer Overflow
CVE-2007-2770remotewindows
Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long
23RISK
open
ReferênciaVexDay Proof
gelato CMS 0.95 - 'img' Remote File Disclosure
CVE-2008-3675webappsphp
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files
23RISK
open
ReferênciaVexDay Proof
Falt4 CMS RC4 - 'FCKeditor' Arbitrary File Upload
CVE-2008-6178webappsphp
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2
23RISK
open
ReferênciaVexDay Proof
OZJournals 2.1.1 - 'id' File Disclosure
CVE-2008-0435webappsphp
Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary
23RISK
open
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1328doswindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
HIS-Webshop - 'his-webshop.pl t' Remote File Disclosure
CVE-2008-1541webappscgi
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
PH Pexplorer 0.24 - 'explorer_load_lang.php' Local File Inclusion
CVE-2006-5510webappsphp
Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbi
23RISK
open
ReferênciaVexDay Proof
MyForum 1.3 - 'lecture.php' SQL Injection
CVE-2008-4760webappsphp
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
FTP Voyager 14.0.0.3 - 'CWD' Remote Stack Overflow (PoC)
CVE-2007-1079doswindows
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a de
23RISK
open
ReferênciaVexDay Proof
TinyButStrong 3.4.0 - 'script' Local File Disclosure
CVE-2009-1653webappsphp
Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
CVE-2009-1328localwindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
Irola My-Time 3.5 - SQL Injection
CVE-2007-6217webappsphp
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
PHPOF 20040226 - 'DB_adodb.class.php' Remote File Inclusion
CVE-2007-4763webappsphp
PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and ear
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6548webappsphp
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators t
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.