Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
CVE-2008-4592webappsphp
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RISK
open
ReferênciaVexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
CVE-2008-6447remotewindows
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
IBM Domino Web Access 7.0 Upload Module - 'inotes6.dll' Remote Buffer Overflow
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open
ReferênciaVexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open
ReferênciaVexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
CVE-2008-4603webappsphp
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
ReferênciaVexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
CVE-2007-4509webappsphp
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RISK
open
ReferênciaVexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
CVE-2008-0437remotewindows
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RISK
open
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
CVE-2009-2099webappsphp
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISK
open
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISK
open
ReferênciaVexDay Proof
Fast Click SQL 1.1.7 Lite - 'init.php' Remote File Inclusion
CVE-2008-4624webappsphp
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allo
23RISK
open
ReferênciaVexDay Proof
Blogator-script 0.95 - Change User Password
CVE-2008-6473webappsphp
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection
CVE-2008-4625webappsphp
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r
23RISK
open
ReferênciaVexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
CVE-2008-4626webappsphp
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RISK
open
ReferênciaVexDay Proof
WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection
CVE-2008-4627webappsphp
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4643webappsphp
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
CVE-2007-4583remotewindows
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISK
open
ReferênciaVexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RISK
open
ReferênciaVexDay Proof
WebFileExplorer 3.1 - 'db.mdb' Database Disclosure
CVE-2009-1495webappsphp
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2160webappsphp
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RISK
open
ReferênciaVexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISK
open
ReferênciaVexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
CVE-2008-6499remotewindows
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
CVE-2008-1087localwindows
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RISK
open
ReferênciaVexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
CVE-2009-1498webappsphp
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RISK
open
ReferênciaVexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
CVE-2008-4674webappsphp
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
CVE-2008-4675webappsphp
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.