Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
CVE-2009-0384webappsphp
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
CVE-2007-3536remotewindows
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open
ReferênciaVexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
CVE-2009-0409webappsphp
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
CVE-2007-3271webappsphp
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
CVE-2008-0422webappsphp
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
CVE-2009-0426webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RISK
open
ReferênciaVexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
CVE-2007-3611webappsphp
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISK
open
ReferênciaVexDay Proof
DMXReady Member Directory Manager 1.1 - SQL Injection
CVE-2009-0427webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and ea
23RISK
open
ReferênciaVexDay Proof
CMS-BRD - 'menuclick' SQL Injection
CVE-2008-2837webappsphp
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the me
23RISK
open
ReferênciaVexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
CVE-2009-0447webappsasp
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
CVE-2007-0839webappsphp
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RISK
open
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2882webappsphp
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers
23RISK
open
ReferênciaVexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
CVE-2006-4713webappsphp
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
emuCMS 0.3 - 'cat_id' SQL Injection
CVE-2008-2891webappsphp
SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
CVE-2008-4510doswindows
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RISK
open
ReferênciaVexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
CVE-2006-5497webappsphp
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RISK
open
ReferênciaVexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
CVE-2008-5042webappsphp
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RISK
open
ReferênciaVexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
CVE-2009-0450localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RISK
open
ReferênciaVexDay Proof
SkaLinks 1.5 - Authentication Bypass
CVE-2009-0451webappsphp
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RISK
open
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0452webappsphp
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RISK
open
ReferênciaVexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
CVE-2006-6078webappsphp
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
CVE-2006-6827doswindows
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RISK
open
ReferênciaVexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
CVE-2006-4672webappsphp
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RISK
open
ReferênciaVexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
CVE-2008-2917webappsasp
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
CVE-2006-5551doswindows
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RISK
open
ReferênciaVexDay Proof
phpBLASTER CMS 1.0 RC1 - Multiple Local File Inclusions
CVE-2008-5171webappsphp
Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals
23RISK
open
ReferênciaVexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
CVE-2006-7169webappsphp
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RISK
open
previouspage 138 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.