Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,207cataloged exploits
36,419CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
easyTrade 2.x - 'id' SQL Injection
CVE-2008-2790webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
DigiAffiliate 1.4 - 'id' SQL Injection
CVE-2007-0306webappsasp
SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
CVE-2007-1704webappsphp
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RISK
open
ReferênciaVexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
CVE-2008-4321doswindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RISK
open
ReferênciaVexDay Proof
FlashGet 1.9.0.1012 - 'FTP PWD Response' Remote Buffer Overflow (SafeSEH)
CVE-2008-4321remotewindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RISK
open
ReferênciaVexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0851webappsphp
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
CVE-2007-1807webappsphp
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RISK
open
ReferênciaVexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2902webappsphp
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users t
23RISK
open
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - SQL Injection
CVE-2007-3461webappsphp
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
PHP123 Top Sites - 'category.php?cat' SQL Injection
CVE-2007-4054webappsphp
SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Blog:CMS 4.2.1b - SQL Injection / Cross-Site Scripting
CVE-2008-0360webappsphp
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_doc - SQL Injection
CVE-2008-0772webappsphp
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module EasyContent - 'page_id' SQL Injection
CVE-2008-0880webappsphp
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
MiaCMS 4.6.5 - Multiple SQL Injections
CVE-2008-3785webappsphp
Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Mambo Component 'com_a6mambocredits' 1.0.0 - Remote File Inclusion
CVE-2006-4288webappsphp
PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits)
23RISK
open
ReferênciaVexDay Proof
openEngine 2.0 beta4 - Remote File Inclusion
CVE-2008-4329webappsphp
PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
Discuz! 5.0.0 GBK - SQL Injection / Admin Credentials Disclosure
CVE-2006-5561webappsphp
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Basic PHP Events Lister 1.0 - SQL Injection
CVE-2008-6464webappsphp
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
DigiRez 3.4 - 'book_id' SQL Injection
CVE-2007-0128webappsasp
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Eskolar CMS 0.9.0.0 - Blind SQL Injection
CVE-2006-3727webappsphp
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
PostNuke Module pnFlashGames 2.5 - SQL Injection
CVE-2008-2013webappsphp
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc
23RISK
open
ReferênciaVexDay Proof
Mambo Module HTMLArea3 1.5 - Remote File Inclusion
CVE-2006-3751webappsphp
PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_html
23RISK
open
ReferênciaVexDay Proof
NuMedia Soft Nms DVD Burning SDK - ActiveX 'NMSDVDX.dll' Command Execution
CVE-2008-4342remotewindows
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used
28RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Snippets 1.02 (c) - Blind SQL Injection
CVE-2007-1962webappsphp
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
eReservations - Authentication Bypass
CVE-2009-0252webappsasp
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
QuickEStore 8.2 - 'insertorder.cfm' SQL Injection
CVE-2007-3933webappsphp
SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Arcadwy Arcade Script - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-1229webappsphp
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u
23RISK
open
ReferênciaVexDay Proof
PHP Real Estate - 'fullnews.php?id' SQL Injection
CVE-2007-6462webappsphp
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'Cuid' cookie Blind SQL Injection
CVE-2008-0734webappsphp
SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attacke
23RISK
open
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3307webappsphp
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.