Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Estate Agent Manager 1.3 - 'default.asp' Authentication Bypass
CVE-2006-5934webappsasp
SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Pre Shopping Mall 1.0 - SQL Injection
CVE-2007-2674webappsphp
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
AJ HYIP ACME - 'readarticle.php' SQL Injection
CVE-2008-4044webappsphp
SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
CVE-2006-2847webappsasp
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2149webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web
23RISK
open
ReferênciaVexDay Proof
bwired - 'index.php?newsID' SQL Injection
CVE-2007-3977webappsphp
Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via un
23RISK
open
ReferênciaVexDay Proof
NoseRub 0.5.2 - Login SQL Injection
CVE-2007-6602webappsphp
SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Command Execution
CVE-2008-4049remotewindows
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot
23RISK
open
ReferênciaVexDay Proof
FlexBB 0.5.5 - '/inc/start.php?_COOKIE' SQL Bypass
CVE-2006-1978webappsphp
SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
iG Calendar 1.0 - 'user.php?id' SQL Injection
CVE-2007-0130webappsphp
SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Okul Web Otomasyon Sistemi 4.0.1 - SQL Injection
CVE-2007-0305webappsasp
SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
CVE-2007-1719localbsd
Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to
23RISK
open
ReferênciaVexDay Proof
wolioCMS - Authentication Bypass / SQL Injection
CVE-2007-4156webappsphp
Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the
23RISK
open
ReferênciaVexDay Proof
AdaptCMS Lite 1.3 - Blind SQL Injection
CVE-2008-4524webappsphp
SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3
23RISK
open
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2178webappsphp
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
DZCP (deV!L_z Clanportal) 1.34 - 'id' SQL Injection
CVE-2006-3347webappsphp
SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
OpenLD 1.2.2 - 'index.php?id' SQL Injection
CVE-2007-3682webappsphp
SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 - SFX Path Stack Overflow
CVE-2006-3912doswindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open
ReferênciaVexDay Proof
phsBlog 0.2 - Bypass SQL Injection Filtering
CVE-2008-4072webappsphp
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - 'Client-IP' SQL Injection
CVE-2007-0971webappsphp
Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
HC Newssystem 1.0-1.4 - 'index.php?ID' SQL Injection
CVE-2007-1417webappsphp
SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
FlashGameScript 1.7 - 'user' SQL Injection
CVE-2007-3646webappsphp
SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ACG News 1.0 - 'aid'/'catid' SQL Injection
CVE-2007-4603webappsphp
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
eXV2 Module bamaGalerie 3.03 - SQL Injection
CVE-2008-1349webappsphp
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows
23RISK
open
ReferênciaVexDay Proof
phpBP RC3 (2.204) FIX4 - SQL Injection
CVE-2008-1408webappsphp
SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Frogss CMS 0.7 - SQL Injection
CVE-2007-2299webappsphp
Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Autodealers CMS AutOnline - 'pageid' SQL Injection
CVE-2008-4073webappsphp
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Tiger PHP News System 1.0b build 39 - SQL Injection
CVE-2008-0469webappsphp
SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
team 1.x - File Disclosure / Cross-Site Scripting
CVE-2009-0761webappsasp
Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web
23RISK
open
ReferênciaVexDay Proof
Coupon Script 4.0 - 'id' SQL Injection
CVE-2008-4090webappsphp
SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.