Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0378webappsphp
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Jo
23RISK
open
ReferênciaVexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
CVE-2006-6552webappsphp
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
CitectSCADA ODBC Server - Remote Stack Buffer Overflow (Metasploit)
CVE-2008-2639remotewindows
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0986webappsphp
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remot
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
CVE-2009-0381webappsphp
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RISK
open
ReferênciaVexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
CVE-2009-0384webappsphp
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
CVE-2007-3536remotewindows
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open
ReferênciaVexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2648webappsphp
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
ezusermanager 1.6 - Remote File Inclusion
CVE-2006-2424webappsphp
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RISK
open
ReferênciaVexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISK
open
ReferênciaVexDay Proof
UltraVNC/TightVNC (Multiple VNC Clients) - Multiple Integer Overflows (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISK
open
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open
ReferênciaVexDay Proof
Motorola Wimax modem CPEi300 - File Disclosure / Cross-Site Scripting
CVE-2009-0393remotehardware
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated user
23RISK
open
ReferênciaVexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
CVE-2009-0405webappsphp
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Webring 1.0 - Remote File Inclusion
CVE-2006-4129webappsphp
PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier
23RISK
open
ReferênciaVexDay Proof
Magic Photo Storage Website - '_config[site_path]' File Inclusion
CVE-2007-0181webappsphp
PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote atta
23RISK
open
ReferênciaVexDay Proof
Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion
CVE-2007-0232webappsphp
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Tropicalm Crowell Resource 4.5.2 - 'RESPATH' Remote File Inclusion
CVE-2007-2530webappsphp
Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Media Gallery for Geeklog 1.4.8a - Remote File Inclusion
CVE-2007-2706webappsphp
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows rem
23RISK
open
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
CVE-2009-0409webappsphp
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
CVE-2007-3271webappsphp
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
CVE-2008-0422webappsphp
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RISK
open
ReferênciaVexDay Proof
PowerPoint Viewer OCX 3.2 - ActiveX Control Denial of Service
CVE-2007-2494doswindows
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote
23RISK
open
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - 'clanek' Blind SQL Injection
CVE-2009-0425webappsphp
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
previouspage 100 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.