Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
phpWebSite 0.10.0-full - 'topics.php' SQL Injection
CVE-2006-0973webappsphp
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
CVE-2006-4239webappsphp
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISK
open
ReferênciaVexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
CVE-2006-4644webappsphp
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2159webappsphp
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote at
23RISK
open
ReferênciaVexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
CVE-2006-6643doswindows
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISK
open
ReferênciaVexDay Proof
photokron 1.7 - Remote Database Disclosure
CVE-2008-0297webappsphp
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISK
open
ReferênciaVexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2666webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote att
23RISK
open
ReferênciaVexDay Proof
Project Based Calendaring System (PBCS) 0.7.1 - Multiple Vulnerabilities
CVE-2008-2215webappsphp
Multiple directory traversal vulnerabilities in Project-Based Calendaring System (PBCS) 0.7.1-1 allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
FreeLyrics 1.0 - Remote File Disclosure
CVE-2008-5861webappsphp
Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via di
23RISK
open
ReferênciaVexDay Proof
Visagesoft eXPert PDF EditorX - 'VSPDFEditorX.ocx' Insecure Method
CVE-2008-6496doswindows
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT
23RISK
open
ReferênciaVexDay Proof
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
CVE-2009-2080webappsphp
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obta
23RISK
open
ReferênciaVexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISK
open
ReferênciaVexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
CVE-2008-1856webappsphp
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RISK
open
ReferênciaVexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6781webappsphp
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open
ReferênciaVexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
CVE-2008-2294webappsphp
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RISK
open
ReferênciaVexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
CVE-2007-0307webappsphp
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
CVE-2008-2753webappsphp
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3434webappsphp
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RISK
open
ReferênciaVexDay Proof
eFiction 3.0 - 'toplists.php' SQL Injection
CVE-2008-2754webappsphp
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.3 - Arbitrary File Delete
CVE-2008-4913webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary
23RISK
open
ReferênciaVexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0852webappsphp
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
23RISK
open
ReferênciaVexDay Proof
Ascended Guestbook 1.0.0 - 'embedded.php' File Inclusion
CVE-2006-5531webappsphp
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
MycroCMS 0.5 - Blind SQL Injection
CVE-2008-2770webappsphp
SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
FishCart 3.2 RC2 - 'fc_example.php' Remote File Inclusion
CVE-2007-4287webappsphp
PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2862webappsphp
Multiple SQL injection vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Simple HTTPd 1.38 - Multiple Vulnerabilities
CVE-2007-6405remotewindows
Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI progra
23RISK
open
ReferênciaVexDay Proof
Mapbender 2.4.4 - 'gaz' SQL Injection
CVE-2008-0301webappsphp
Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
ReferênciaVexDay Proof
NewLife Blogger 3.0 - Insecure Cookie Handling / SQL Injection
CVE-2008-6180webappsphp
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows
23RISK
open
ReferênciaVexDay Proof
ComVironment 4.0 - 'grab_globals.lib.php' Remote File Inclusion
CVE-2007-0395webappsphp
PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Phaos R4000 Version - 'file' Remote File Disclosure
CVE-2008-1755webappsphp
Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote att
23RISK
open
previouspage 102 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.