Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
MKPortal NoBoard Module (Beta) - Remote File Inclusion
CVE-2007-3813webappsphp
PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attack
35RISK
open
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISK
open
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.1 - HttpDownloadFile() Insecure Method
CVE-2007-4420remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer
23RISK
open
ReferênciaVexDay Proof
Macrovision FlexNet DownloadManager - Insecure Methods
CVE-2008-4587remotewindows
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.
28RISK
open
ReferênciaVexDay Proof
Shop Script Pro 2.12 - SQL Injection
CVE-2009-2023webappsphp
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RISK
open
ReferênciaVexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
CVE-2009-2034webappsphp
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RISK
open
ReferênciaVexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RISK
open
ReferênciaVexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
CVE-2008-4603webappsphp
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
ReferênciaVexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
CVE-2007-4509webappsphp
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RISK
open
ReferênciaVexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
CVE-2008-0437remotewindows
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RISK
open
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
CVE-2009-2099webappsphp
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection
CVE-2008-4625webappsphp
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r
23RISK
open
ReferênciaVexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
CVE-2008-4626webappsphp
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RISK
open
ReferênciaVexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RISK
open
ReferênciaVexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
CVE-2008-6499remotewindows
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
CVE-2008-1087localwindows
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RISK
open
ReferênciaVexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
CVE-2009-1498webappsphp
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RISK
open
ReferênciaVexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
CVE-2008-4674webappsphp
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
CVE-2008-4675webappsphp
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
CVE-2008-4682dosmultiple
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
23RISK
open
ReferênciaVexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RISK
open
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4807webappsphp
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
Peachtree Accounting 2004 - 'PAWWeb11.ocx' ActiveX Insecure Method
CVE-2008-4699remotewindows
Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers
28RISK
open
ReferênciaVexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
CVE-2008-4706webappsphp
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
CVE-2007-4921webappsphp
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RISK
open
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
CVE-2007-4922webappsphp
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.