Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
CVE-2008-2691webappsasp
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
AJ HYIP ACME - 'comment.php' SQL Injection
CVE-2008-4043webappsphp
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
CVE-2008-6913webappsphp
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
CVE-2008-6923webappsphp
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Joomla! Component yvComment 1.16 - Blind SQL Injection
CVE-2008-2692webappsphp
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISK
open
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISK
open
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
CVE-2008-2697webappsphp
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RISK
open
ReferênciaVexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
CVE-2008-2742webappsphp
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISK
open
ReferênciaVexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
CVE-2008-4135doshardware
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open
ReferênciaVexDay Proof
JAMM CMS - 'id' Blind SQL Injection
CVE-2008-2755webappsphp
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the i
23RISK
open
ReferênciaVexDay Proof
CKGold Shopping Cart 2.5 - 'category_id' SQL Injection
CVE-2008-2774webappsphp
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
RevokeBB 1.0 RC11 - 'Search' SQL Injection
CVE-2008-2778webappsphp
SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6947webappsphp
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via un
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_pcchess - Blind SQL Injection
CVE-2009-0379webappsphp
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
MyMarket 1.72 - Blind SQL Injection
CVE-2008-2815webappsphp
SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2080remotewindows
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
CVE-2008-2817webappsphp
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Discuz! 6.x/7.x - Remote Code Execution
CVE-2008-6958webappsphp
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via
23RISK
open
ReferênciaVexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
CVE-2007-2089webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RISK
open
ReferênciaVexDay Proof
LE.CMS 1.4 - Arbitrary File Upload
CVE-2008-2833webappsphp
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload a
23RISK
open
ReferênciaVexDay Proof
IGSuite 3.2.4 - Reverse Shell / Blind SQL Injection
CVE-2008-2835webappsphp
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2838webappsphp
Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine Category Addon - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
CVE-2008-6983webappsphp
modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer
23RISK
open
ReferênciaVexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2839webappsphp
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
XChat 2.8.7b - 'URI Handler' Remote Code Execution (Internet Explorer 6/7)
CVE-2008-2841remotewindows
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote a
28RISK
open
ReferênciaVexDay Proof
Easy Webstore 1.2 - SQL Injection
CVE-2008-2853webappsphp
SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.