Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
CVE-2008-6919webappsphp
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RISK
open
ReferênciaVexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
CVE-2006-4234webappsphp
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
CVE-2008-6995doswindows
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RISK
open
ReferênciaVexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
CVE-2007-6223webappsphp
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
CVE-2006-4242webappsphp
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RISK
open
ReferênciaVexDay Proof
RealPlayer 11 - '.au' Denial of Service
CVE-2007-6235doswindows
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISK
open
ReferênciaVexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
CVE-2007-6231webappsphp
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Snitz Forums 2000 - 'Active.asp' SQL Injection
CVE-2007-6240webappsasp
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
CVE-2006-4296webappsphp
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RISK
open
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
CVE-2006-4300webappsphp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
CVE-2006-4301doswindows
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISK
open
ReferênciaVexDay Proof
Texas Imperial Software WFTPD 3.23 - 'SIZE' Remote Buffer Overflow
CVE-2006-4318remotewindows
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISK
open
ReferênciaVexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
CVE-2006-4343dosmultiple
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISK
open
ReferênciaVexDay Proof
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow
CVE-2007-6258remotelinux
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RISK
open
ReferênciaVexDay Proof
Apple Mac OSX 10.5.0 (Leopard) - vpnd Remote Denial of Service (PoC)
CVE-2007-6276dososx
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows
23RISK
open
ReferênciaVexDay Proof
MDaemon POP3 Server < 9.06 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-4364doswindows
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISK
open
ReferênciaVexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
CVE-2007-6310webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbit
23RISK
open
ReferênciaVexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISK
open
ReferênciaVexDay Proof
xml2owl 0.1.1 - 'filedownload.php' Remote File Disclosure
CVE-2007-6322webappsphp
Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6331remotewindows
Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP
35RISK
open
ReferênciaVexDay Proof
phpGroupWare 0.9.16.010 - 'GLOBALS[]' Remote Code Execution
CVE-2006-4458webappsphp
Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allow
23RISK
open
ReferênciaVexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
CVE-2007-6391webappsphp
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4586webappsphp
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticat
23RISK
open
ReferênciaVexDay Proof
TikiWiki 1.9 Sirius - 'jhot.php' Remote Command Execution
CVE-2006-4602webappsphp
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open
ReferênciaVexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
CVE-2007-6393webappsphp
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6395webappsphp
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open
previouspage 106 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.