Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
CVE-2009-1677webappsphp
Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 an
23RISK
open
ReferênciaVexDay Proof
Online Grades & Attendance 3.2.6 - Multiple Local File Inclusions
CVE-2009-2037webappsphp
Multiple directory traversal vulnerabilities in Online Grades & Attendance 3.2.5 and earlier, and possibly 3.2.6, when r
23RISK
open
ReferênciaVexDay Proof
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
CVE-2006-2284webappsphp
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
CVE-2008-3241webappsphp
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
ASP Portal - Multiple SQL Injections
CVE-2008-5605webappsasp
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7097webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
CVE-2009-1767webappsphp
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RISK
open
ReferênciaVexDay Proof
3editor CMS 0.42 - 'index.php' Local File Inclusion
CVE-2006-6877webappsphp
Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
Relative Real Estate Systems 3.0 - 'listing_id' SQL Injection
CVE-2008-2881webappsphp
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dep
23RISK
open
ReferênciaVexDay Proof
F3Site 2.1 - Remote Code Execution
CVE-2007-0764webappsphp
Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload an
23RISK
open
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3308webappsphp
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals
23RISK
open
ReferênciaVexDay Proof
e107 < 0.7.8 - 'photograph' Arbitrary File Upload
CVE-2007-3429webappsphp
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allow
23RISK
open
ReferênciaVexDay Proof
CMS Ortus 1.13 - SQL Injection
CVE-2008-6282webappsphp
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Vivvo CMS 3.4 - 'index.php' Blind SQL Injection
CVE-2007-3939webappsphp
SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlie
23RISK
open
ReferênciaVexDay Proof
lustig.cms Beta 2.5 - 'forum.php?view' Remote File Inclusion
CVE-2007-5138webappsphp
PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Litespeed Web Server 3.2.3 - Source Code Disclosure
CVE-2007-5654remotemultiple
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
35RISK
open
ReferênciaVexDay Proof
phpFaber URLInn 2.0.5 - 'dir_ws' Remote File Inclusion
CVE-2007-5754webappsphp
PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
CVE-2008-5860webappsphp
Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is
23RISK
open
ReferênciaVexDay Proof
PowerClan 1.14a - Authentication Bypass
CVE-2009-0707webappsphp
SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Realty Web-Base 1.0 - Authentication Bypass
CVE-2009-1658webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remot
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9 - Remote File Inclusion
CVE-2006-2392webappsphp
PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.
23RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5742webappsphp
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbit
23RISK
open
ReferênciaVexDay Proof
Intel 2200BG 802.11 - disassociation packet Kernel Memory Corruption
CVE-2007-0686doswindows
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of servi
23RISK
open
ReferênciaVexDay Proof
PHPfan 3.3.4 - 'init.php' Remote File Inclusion
CVE-2008-6251webappsphp
PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6524webappsphp
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrar
23RISK
open
ReferênciaVexDay Proof
Dagger CMS 2008 - 'dir_inc' Remote File Inclusion
CVE-2008-6635webappsphp
PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when re
23RISK
open
ReferênciaVexDay Proof
wpQuiz 2.7 - Multiple SQL Injections
CVE-2007-6172webappsphp
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id
23RISK
open
ReferênciaVexDay Proof
Joomla! Component gigCalendar 1.0 - SQL Injection
CVE-2009-0726webappsphp
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers
23RISK
open
ReferênciaVexDay Proof
123tkShop 0.9.1 - Remote Authentication Bypass
CVE-2007-6458webappsphp
SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL com
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.