Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
CVE-2008-6328webappsphp
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload
CVE-2008-0457remotewindows
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISK
open
ReferênciaVexDay Proof
Pre Job Board - Authentication Bypass
CVE-2008-6329webappsphp
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
MyTopix 1.3.0 - SQL Injection
CVE-2008-6330webappsphp
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RISK
open
ReferênciaVexDay Proof
Simple Customer 1.2 - Authentication Bypass
CVE-2008-6332webappsphp
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Apple QuickTime 7.5.5 / iTunes 8.0 - Remote Off-by-One Crash
CVE-2008-4116dosmultiple
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr
28RISK
open
ReferênciaVexDay Proof
RSS Simple News - SQL Injection
CVE-2008-6333webappsphp
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RISK
open
ReferênciaVexDay Proof
Extract Website - 'Filename' File Disclosure
CVE-2008-6334webappsphp
Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary f
23RISK
open
ReferênciaVexDay Proof
MailBee WebMail Pro 4.1 - Remote File Disclosure
CVE-2008-0333webappsasp
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET all
28RISK
open
ReferênciaVexDay Proof
Online Keyword Research Tool - 'download.php' File Disclosure
CVE-2008-6335webappsphp
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to rea
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ProDesk 1.0/1.2 - Local File Inclusion
CVE-2008-6222webappsphp
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows
43RISK
open
ReferênciaVexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
CVE-2007-2209localwindows
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RISK
open
ReferênciaVexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
CVE-2008-6336webappsphp
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_noticias 1.0 - SQL Injection
CVE-2008-0670webappsphp
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attacker
23RISK
open
ReferênciaVexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
CVE-2008-6345webappsphp
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
A-Blog 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-0677webappsphp
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
CVE-2008-6347webappsphp
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISK
open
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-0678webappsphp
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open
ReferênciaVexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
CVE-2006-0821webappsphp
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
CVE-2007-6327doswindows
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RISK
open
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
CVE-2008-2595dosmultiple
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RISK
open
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - SQL Injection
CVE-2008-0683webappsphp
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RISK
open
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
Social Groupie - 'id' SQL Injection
CVE-2008-6358webappsphp
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
CVE-2006-2849webappsphp
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RISK
open
previouspage 136 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.