Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
flinx 1.3 - 'id' SQL Injection
CVE-2008-0468webappsphp
SQL injection vulnerability in category.php in Flinx 1.3 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Move Networks Upgrade Manager Control - Remote Buffer Overflow
CVE-2008-0477remotewindows
Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgra
28RISK
open
ReferênciaVexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0480webappsasp
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary
23RISK
open
ReferênciaVexDay Proof
saPHP Lesson 2.0 - 'forumid' SQL Injection
CVE-2005-3363webappsphp
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
CVE-2006-5851localosx
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RISK
open
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
CVE-2006-5852localosx
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RISK
open
ReferênciaVexDay Proof
Mercury Mail Transport System 4.01b - PH SERVER Remote Overflow
CVE-2005-4411remotewindows
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RISK
open
ReferênciaVexDay Proof
Munch Pro 1.0 - 'switch.asp' SQL Injection
CVE-2006-5880webappsasp
SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Bigware Shop 2.0 - 'pollid' SQL Injection
CVE-2008-0498webappsphp
SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpMyClub 0.0.1 - 'page_courante' Local File Inclusion
CVE-2008-0501webappsphp
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local file
23RISK
open
ReferênciaVexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
CVE-2006-0888dosmultiple
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RISK
open
ReferênciaVexDay Proof
Persits XUpload 3.0 - 'AddFile()' Remote Buffer Overflow
CVE-2008-0492remotewindows
Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUplo
43RISK
open
ReferênciaVexDay Proof
WordPress Plugin Adserve 0.2 - 'adclick.php' SQL Injection
CVE-2008-0507webappsphp
SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Helix Server 11.0.1 (Windows 2000 SP4) - Remote Heap Overflow
CVE-2006-6026remotewindows
Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.
28RISK
open
ReferênciaVexDay Proof
Gallery 2.0.3 - 'stepOrder[]' Remote Command Execution
CVE-2006-1219webappsphp
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include
23RISK
open
ReferênciaVexDay Proof
WORK System E-Commerce 3.0.1 - Remote File Inclusion
CVE-2006-6041webappsphp
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other ver
23RISK
open
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'editor.php' Remote File Inclusion
CVE-2006-6042webappsphp
PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is e
23RISK
open
ReferênciaVexDay Proof
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
CVE-2006-6047webappsphp
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to
23RISK
open
ReferênciaVexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
CVE-2006-6051webappsphp
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RISK
open
ReferênciaVexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
CVE-2006-1610webappsphp
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RISK
open
ReferênciaVexDay Proof
Photo Cart 3.9 - 'adminprint.php' Remote File Inclusion
CVE-2006-6093webappsphp
Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attacker
23RISK
open
ReferênciaVexDay Proof
WebspotBlogging 3.0.1 - 'path' Remote File Inclusion
CVE-2006-2860webappsphp
PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code v
28RISK
open
ReferênciaVexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
CVE-2006-2888webappsphp
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
CVE-2006-2863webappsphp
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
CVE-2006-2929webappsphp
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earl
23RISK
open
ReferênciaVexDay Proof
blur6ex 0.3.462 - 'ID' Admin Disclosure / Blind SQL Injection
CVE-2006-3065webappsphp
SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
fipsGallery 1.5 - 'index1.asp' SQL Injection
CVE-2006-6117webappsasp
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6137webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6138webappsphp
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary director
23RISK
open
ReferênciaVexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
CVE-2006-4158webappsphp
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RISK
open
previouspage 133 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.