Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! Component mosDirectory 2.3.2 - Remote File Inclusion
CVE-2007-6555webappsphp
PHP remote file inclusion vulnerability in modules/mod_pxt_latest.php in the mosDirectory (com_directory) 2.3.2 componen
23RISK
open
ReferênciaVexDay Proof
zBlog 1.2 - SQL Injection
CVE-2007-6577webappsphp
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHP ZLink 0.3 - 'go.php' SQL Injection
CVE-2007-6578webappsphp
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Wallpaper Site 1.0.09 - 'category.php' SQL Injection
CVE-2007-6580webappsphp
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
CVE-2007-6584webappsphp
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
CVE-2007-6585webappsphp
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
CVE-2007-6605doswindows
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Haberx 1.02 < 1.1 - 'tr' SQL Injection
CVE-2006-4853webappsasp
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
aeDating 4.1 - dir[inc] Remote File Inclusion
CVE-2006-4870webappsphp
Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attacker
23RISK
open
ReferênciaVexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
CVE-2008-0326webappsphp
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
LulieBlog 1.02 - SQL Injection
CVE-2008-0446webappsphp
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
JW Player - 'playerready' Cross-Site Scripting
CVE-2012-3351webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
CVE-2007-6615webappsphp
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6622webappsphp
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
IPTBB 0.5.4 - 'id' SQL Injection
CVE-2007-6639webappsphp
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Exponent CMS 0.96.3 - 'view' Remote Command Execution
CVE-2006-4963webappsphp
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitr
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
CVE-2008-0827webappsphp
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
SanyBee Gallery 0.1.1 - 'p' Local File Inclusion
CVE-2007-6648webappsphp
Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
matpo bilder galerie 1.1 - Remote File Inclusion
CVE-2007-6649webappsphp
PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
CVE-2007-6650webappsphp
Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbit
23RISK
open
ReferênciaVexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
CVE-2007-6651webappsphp
Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive infor
23RISK
open
ReferênciaVexDay Proof
XCMS 1.83 - Remote Command Execution
CVE-2007-6652webappsphp
cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Host 2.0.7 - 'download.php' Remote File Disclosure
CVE-2007-6653webappsphp
Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary
23RISK
open
ReferênciaVexDay Proof
oneSCHOOL - 'admin/login.asp' SQL Injection
CVE-2007-6665webappsasp
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
ZenPhoto 1.1.3 - 'rss.php?albumnr' SQL Injection
CVE-2007-6666webappsphp
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Forum Host 3.0.x - Remote File Inclusion
CVE-2007-6657webappsphp
PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier
23RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 (Final) - Multiple SQL Injections
CVE-2007-6667webappsphp
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Bitweaver 2.8.1 - Multiple Vulnerabilities
CVE-2012-5193webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbi
23RISK
open
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'sort' SQL Injection
CVE-2006-5030webappsphp
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users
23RISK
open
previouspage 149 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.