Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2841webappsphp
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
CVE-2008-2902webappsphp
SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Phaos 0.9.2 - 'basename()' Remote Command Execution
CVE-2006-4420webappsphp
Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local
23RISK
open
ReferênciaVexDay Proof
PHP Crawler 0.8 - Remote File Inclusion
CVE-2008-4137webappsphp
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
NuralStorm Webmail 0.98b - 'process.php' Remote File Inclusion
CVE-2006-5386webappsphp
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is
23RISK
open
ReferênciaVexDay Proof
Fuzzylime CMS 3.03 - 'track.php' Local File Inclusion
CVE-2008-5291webappsphp
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arb
23RISK
open
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6381webappsasp
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files vi
23RISK
open
ReferênciaVexDay Proof
ASP-Nuke Community 1.5 - Cookie Privilege Escalation
CVE-2006-7152webappsasp
default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo c
23RISK
open
ReferênciaVexDay Proof
Maran PHP Shop - 'admin.php' Insecure Cookie Handling
CVE-2008-6296webappsphp
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open
ReferênciaVexDay Proof
McGallery 0.5b - 'download.php' Arbitrary File Download
CVE-2007-1478webappsphp
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil
23RISK
open
ReferênciaVexDay Proof
OpenForum 0.66 Beta - Remote Reset Admin Password
CVE-2008-7066webappsphp
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct req
23RISK
open
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2134webappsphp
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url param
23RISK
open
ReferênciaVexDay Proof
PBLang 4.67.16.a - Remote Code Execution
CVE-2007-3096webappsphp
Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled,
23RISK
open
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0350webappsphp
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows re
23RISK
open
ReferênciaVexDay Proof
freePHPgallery 0.6 - Cookie Local File Inclusion
CVE-2008-0818webappsphp
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitra
23RISK
open
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1772webappsphp
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RISK
open
ReferênciaVexDay Proof
IndexScript 2.8 - 'cat_id' SQL Injection
CVE-2007-4069webappsphp
SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection
CVE-2008-3784webappsphp
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows rem
23RISK
open
ReferênciaVexDay Proof
Cuteflow Bin 1.5.0 - 'login.php' Local File Inclusion
CVE-2008-1493webappsphp
Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbi
23RISK
open
ReferênciaVexDay Proof
Dayfox Blog 4 - Multiple Local File Inclusions
CVE-2008-3564webappsphp
Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
OTManager CMS 24a - Local File Inclusion / Cross-Site Scripting
CVE-2008-5201webappsphp
Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
team 1.x - File Disclosure / Cross-Site Scripting
CVE-2009-0760webappsasp
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
ReferênciaVexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1771webappsphp
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open
ReferênciaVexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
CVE-2007-0558webappsphp
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
CVE-2007-2158webappsphp
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
CVE-2008-2349webappsphp
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RISK
open
ReferênciaVexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PacPoll 4.0 - Database Disclosure
CVE-2008-5981webappsphp
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RISK
open
previouspage 153 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.