Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' 'HREF' Universal Buffer Overflow
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISK
open
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (2)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RISK
open
ReferênciaVexDay Proof
Quake 3 Engine Client (Windows x86) - CS_ITEms Remote Overflow
CVE-2006-3401doswindows_x86
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
Activist Mobilization Platform (AMP) 3.2 - Remote File Inclusion
CVE-2007-1571webappsphp
PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2
23RISK
open
ReferênciaVexDay Proof
Scribe 0.2 - PHP Remote Code Execution
CVE-2007-5822webappsphp
Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - IPv6-ipcomp Remote kernel Denial of Service (PoC)
CVE-2008-0177dosmultiple
The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check th
28RISK
open
ReferênciaVexDay Proof
EntertainmentScript 1.4.0 - 'play.php' SQL Injection
CVE-2008-2393webappsphp
SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Multi-Threaded TFTP 1.1 - GET Denial of Service
CVE-2006-4781doswindows
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
The Walking Club - Authentication Bypass
CVE-2009-0281webappsasp
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
TotalCalendar 2.30 - 'inc' Remote File Inclusion
CVE-2006-7055webappsphp
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
OpenGoo 1.1 - Local File Inclusion
CVE-2009-0286webappsphp
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
CVE-2007-4010localwindows
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RISK
open
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RISK
open
ReferênciaVexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
CVE-2009-0301remotewindows
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RISK
open
ReferênciaVexDay Proof
SunOS Release 5.11 snv_101b - Remote IPv6 Crash
CVE-2009-0304dossolaris
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
CMS MAXSITE 1.10 - 'category' SQL Injection
CVE-2008-2487webappsphp
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
MetaForum 0.513 Beta - Arbitrary File Upload
CVE-2007-1552webappsphp
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type
23RISK
open
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-0623doswindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISK
open
ReferênciaVexDay Proof
Free Bible Search PHP Script - SQL Injection
CVE-2009-0327webappsphp
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
CVE-2008-5705remotelinux
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISK
open
ReferênciaVexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
CVE-2007-5914webappsphp
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISK
open
ReferênciaVexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
CVE-2009-0331webappsphp
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RISK
open
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0334webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2535webappsphp
Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
CVE-2009-0350doswindows
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RISK
open
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Mail Machine 3.989 - Local File Inclusion
CVE-2007-3702webappsphp
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RISK
open
previouspage 131 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.