Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,108cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Cuteflow Bin 1.5.0 - 'login.php' Local File Inclusion
CVE-2008-1493webappsphp
Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbi
23RISK
open
ReferênciaVexDay Proof
Dayfox Blog 4 - Multiple Local File Inclusions
CVE-2008-3564webappsphp
Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
OTManager CMS 24a - Local File Inclusion / Cross-Site Scripting
CVE-2008-5201webappsphp
Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
team 1.x - File Disclosure / Cross-Site Scripting
CVE-2009-0760webappsasp
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
ReferênciaVexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1771webappsphp
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which
23RISK
open
ReferênciaVexDay Proof
microssys CMS 1.5 - Remote File Inclusion
CVE-2008-2396webappsphp
PHP remote file inclusion vulnerability in index.php in Wajox Software microSSys CMS 1.5 and earlier, when register_glob
23RISK
open
ReferênciaVexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3721webappsphp
PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
wotw 5.0 - Local/Remote File Inclusion
CVE-2008-6223webappsphp
PHP remote file inclusion vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
GRBoard 1.8 - Multiple Remote File Inclusions
CVE-2009-0444webappsphp
Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc
23RISK
open
ReferênciaVexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
CVE-2009-1248webappsphp
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
CVE-2008-6001webappsphp
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6398webappsphp
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar
23RISK
open
ReferênciaVexDay Proof
RantX 1.0 - Insecure Admin Authentication
CVE-2008-2297webappsphp
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RISK
open
ReferênciaVexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
CVE-2008-6291webappsphp
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RISK
open
ReferênciaVexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6613webappsphp
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
CVE-2008-6963webappsphp
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RISK
open
ReferênciaVexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
CVE-2009-1752webappsphp
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open
ReferênciaVexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
CVE-2007-0558webappsphp
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
CVE-2007-2158webappsphp
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
CVE-2008-2349webappsphp
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RISK
open
ReferênciaVexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PacPoll 4.0 - Database Disclosure
CVE-2008-5981webappsphp
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RISK
open
ReferênciaVexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
CVE-2006-2881webappsphp
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RISK
open
ReferênciaVexDay Proof
Clever Copy 3.0 - 'results.php' SQL Injection
CVE-2008-2909webappsphp
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2911webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arb
23RISK
open
ReferênciaVexDay Proof
PHPMyphorum 1.5a - '/mep/frame.php' Remote File Inclusion
CVE-2007-0361webappsphp
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
CVE-2008-4662webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
Net-Side.net CMS - 'index.php?cms' Remote File Inclusion
CVE-2007-1707webappsphp
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows rem
23RISK
open
previouspage 108 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.