Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
CVE-2008-3924webappsphp
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web
23RISK
open
ReferênciaVexDay Proof
UStore 1.0 - 'detail.asp' SQL Injection
CVE-2006-5891webappsasp
SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Estate Agent Manager 1.3 - 'default.asp' Authentication Bypass
CVE-2006-5934webappsasp
SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Pre Shopping Mall 1.0 - SQL Injection
CVE-2007-2674webappsphp
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
AJ HYIP ACME - 'readarticle.php' SQL Injection
CVE-2008-4044webappsphp
SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
CVE-2006-2847webappsasp
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2149webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web
23RISK
open
ReferênciaVexDay Proof
bwired - 'index.php?newsID' SQL Injection
CVE-2007-3977webappsphp
Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via un
23RISK
open
ReferênciaVexDay Proof
NoseRub 0.5.2 - Login SQL Injection
CVE-2007-6602webappsphp
SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'LIBC TZ' Enviroment Variable Privilege Escalation
CVE-2006-5556localhp-ux
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other ve
23RISK
open
ReferênciaVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1283webappsphp
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows rem
23RISK
open
ReferênciaVexDay Proof
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
CVE-2009-2153webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject a
23RISK
open
ReferênciaVexDay Proof
Mambo Component Pearl 1.6 - Multiple Remote File Inclusions
CVE-2006-3340webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is ena
28RISK
open
ReferênciaVexDay Proof
ASP EDGE 1.2b - 'user.asp' SQL Injection
CVE-2007-0560webappsasp
SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WSN Guest 1.21 - 'id' SQL Injection
CVE-2007-1517webappsphp
SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
TaskDriver 1.2 - Authentication Bypass / SQL Injection
CVE-2007-2622webappsphp
Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3293webappsphp
SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
CVE-2020-23934webappsphp
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RISK
open
ReferênciaVexDay Proof
MyioSoft EasyBookMarker 4.0 - Authentication Bypass
CVE-2008-5652webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
DataLife Engine 4.1 - SQL Injection
CVE-2006-3221webappsphp
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
DataLife Engine 4.1 - SQL Injection
CVE-2006-3221webappsphp
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Mole Group Airline Ticket Script - SQL Injection
CVE-2008-6225webappsphp
SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Md-Pro 1.0.8x - Topics topicid SQL Injection
CVE-2007-3938webappsphp
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attac
23RISK
open
ReferênciaVexDay Proof
MailMachine Pro 2.2.4 - SQL Injection
CVE-2007-6551webappsphp
SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote atta
23RISK
open
ReferênciaVexDay Proof
Coupon Script 4.0 - 'id' SQL Injection
CVE-2008-4090webappsphp
SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Web Directory Script 1.5.3 - 'site' SQL Injection
CVE-2008-4091webappsphp
SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
SimpleBlog 2.3 - 'id' SQL Injection
CVE-2006-4592webappsasp
Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to c
23RISK
open
ReferênciaVexDay Proof
Katalog Plyt Audio (pl) 1.0 - SQL Injection
CVE-2007-1612webappsphp
SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
EQdkp 1.3.2 - 'listmembers.php' SQL Injection
CVE-2007-3077webappsphp
SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Pagetool 1.07 - 'news_id' SQL Injection
CVE-2007-3402webappsphp
SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
previouspage 162 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.