Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
asp-project 1.0 - Insecure Cookie Method
CVE-2009-0280webappsasp
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RISK
open
ReferênciaVexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
CVE-2009-1739webappsphp
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RISK
open
ReferênciaVexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
CVE-2006-6673doswindows
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RISK
open
ReferênciaVexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
CVE-2008-5209webappsphp
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RISK
open
ReferênciaVexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
CVE-2007-0300webappsphp
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ibase 2.03 - Remote File Disclosure
CVE-2008-6288webappsphp
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
CVE-2007-2184webappsphp
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
CVE-2009-1602doswindows
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RISK
open
ReferênciaVexDay Proof
MiniWeb HTTP Server 0.8.x - Remote Denial of Service
CVE-2007-3159doswindows
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negat
23RISK
open
ReferênciaVexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
CVE-2009-1735webappsphp
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RISK
open
ReferênciaVexDay Proof
Picturesolution 2.1 - 'config.php?path' Remote File Inclusion
CVE-2007-5313webappsphp
PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
kontakt formular 1.4 - Remote File Inclusion
CVE-2007-6655webappsphp
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Noticeware E-mail Server 5.1.2.2 - 'POP3' Denial of Service
CVE-2008-6185doswindows
NoticeWare Email Server NG 5.1.2.2 allows remote attackers to cause a denial of service (crash) via multiple POP3 reques
23RISK
open
ReferênciaVexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1557webappsphp
BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/con
23RISK
open
ReferênciaVexDay Proof
phpWebSite 0.10.0-full - 'topics.php' SQL Injection
CVE-2006-0973webappsphp
SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
OPT Max 1.2.0 - 'CRM_inc' Remote File Inclusion
CVE-2006-4239webappsphp
PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allo
23RISK
open
ReferênciaVexDay Proof
phpFullAnnu 5.1 - 'repmod' Remote File Inclusion
CVE-2006-4644webappsphp
PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2159webappsphp
backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote at
23RISK
open
ReferênciaVexDay Proof
Star FTP Server 1.10 - 'RETR' Remote Denial of Service
CVE-2006-6643doswindows
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RE
23RISK
open
ReferênciaVexDay Proof
photokron 1.7 - Remote Database Disclosure
CVE-2008-0297webappsphp
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which inclu
23RISK
open
ReferênciaVexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RISK
open
ReferênciaVexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
CVE-2008-1856webappsphp
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RISK
open
ReferênciaVexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6781webappsphp
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RISK
open
ReferênciaVexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
CVE-2008-2294webappsphp
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RISK
open
ReferênciaVexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
CVE-2007-0307webappsphp
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
CVE-2008-2753webappsphp
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3434webappsphp
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RISK
open
ReferênciaVexDay Proof
eFiction 3.0 - 'toplists.php' SQL Injection
CVE-2008-2754webappsphp
SQL injection vulnerability in toplists.php in eFiction 3.0 and 3.4.3, when magic_quotes_gpc is disabled, allows remote
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.3 - Arbitrary File Delete
CVE-2008-4913webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary
23RISK
open
ReferênciaVexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0852webappsphp
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
23RISK
open
previouspage 142 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.