Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,207cataloged exploits
36,419CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Garennes 0.6.1 - 'repertoire_config' Remote File Inclusion
CVE-2007-2298webappsphp
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
iyzi Forum 1.0b3 - Database Disclosure
CVE-2008-5901webappsphp
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
GoSamba 1.0.1 - 'INCLUDE_PATH' Multiple Remote File Inclusions
CVE-2007-5786webappsphp
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
CVE-2008-2938remotemultiple
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISK
open
ReferênciaVexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
CVE-2006-6849webappsphp
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RISK
open
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4933webappsphp
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RISK
open
ReferênciaVexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5055webappsphp
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6396webappsphp
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RISK
open
ReferênciaVexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
CVE-2008-0278webappsphp
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2534webappsphp
Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
CubeCart 3.0.6 - Remote Command Execution
CVE-2006-0064webappsphp
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6501webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable
23RISK
open
ReferênciaVexDay Proof
inertianews 0.02b - 'inertianews_main.php' Remote File Inclusion
CVE-2006-6726webappsphp
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
EQdkp 1.3.1 - 'Referer Spoof' Remote Database Backup
CVE-2007-0760webappsphp
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an adm
23RISK
open
ReferênciaVexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
CVE-2008-0724webappsphp
The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext
23RISK
open
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-2962webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or H
23RISK
open
ReferênciaVexDay Proof
Google Chrome 1.0.154.43 - Clickjacking
CVE-2009-0374remotewindows
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action th
23RISK
open
ReferênciaVexDay Proof
snetworks PHP Classifieds 5.0 - Remote File Inclusion
CVE-2008-0137webappsphp
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
WebText 0.4.5.2 - Remote Code Execution
CVE-2006-6856webappsphp
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
MODx CMS 0.9.6.2 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-5938webappsphp
PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier,
23RISK
open
ReferênciaVexDay Proof
FTP Explorer 1.0.1 Build 047 - Remote CPU Consumption (Denial of Service)
CVE-2007-1082doswindows
FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CP
23RISK
open
ReferênciaVexDay Proof
XCMS 1.1 - 'Galerie.php' Local File Inclusion
CVE-2007-3523webappsphp
Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7045webappsphp
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll
23RISK
open
ReferênciaVexDay Proof
PHPortal 1.0 - Insecure Cookie Handling
CVE-2009-2117webappsphp
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open
ReferênciaVexDay Proof
WWWISIS 7.1 - 'IsisScript' Local File Disclosure / Cross-Site Scripting
CVE-2007-5455webappscgi
Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
CVE-2009-1066webappsphp
SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1779webappsphp
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Flash Uploader 2.5.1 - Remote File Inclusion
CVE-2007-5457webappsphp
Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash
35RISK
open
ReferênciaVexDay Proof
KwsPHP 1.0 Module Newsletter - SQL Injection
CVE-2007-5458webappsphp
SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, all
23RISK
open
ReferênciaVexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2912webappsphp
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PH
23RISK
open
previouspage 111 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.