Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
CVE-2007-2889webappsphp
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
CVE-2008-2018webappsphp
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
CVE-2007-4046webappsphp
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RISK
open
ReferênciaVexDay Proof
DreamNews Manager - 'id' SQL Injection
CVE-2008-3189webappsphp
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
CVE-2007-4637webappsphp
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RISK
open
ReferênciaVexDay Proof
P2P Foxy - Out of Memory Denial of Service
CVE-2008-6742doswindows
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RISK
open
ReferênciaVexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
CVE-2008-3191webappsphp
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RISK
open
ReferênciaVexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-1450webappsphp
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Shop-Script 2.0 - 'index.php' Remote File Disclosure
CVE-2008-0158webappsphp
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
DesktopOnNet 3 Beta - Multiple Remote File Inclusions
CVE-2008-2649webappsphp
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
LulieBlog 1.0.1 - Remote Authentication Bypass
CVE-2008-0329webappsphp
LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_r
23RISK
open
ReferênciaVexDay Proof
Avlc Forum - 'vlc_forum.php' SQL Injection
CVE-2008-3200webappsphp
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
CVE-2006-2284webappsphp
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP co
23RISK
open
ReferênciaVexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
CVE-2008-3241webappsphp
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
ASP Portal - Multiple SQL Injections
CVE-2008-5605webappsasp
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RISK
open
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7097webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
CVE-2009-1767webappsphp
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RISK
open
ReferênciaVexDay Proof
3editor CMS 0.42 - 'index.php' Local File Inclusion
CVE-2006-6877webappsphp
Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
Relative Real Estate Systems 3.0 - 'listing_id' SQL Injection
CVE-2008-2881webappsphp
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dep
23RISK
open
ReferênciaVexDay Proof
F3Site 2.1 - Remote Code Execution
CVE-2007-0764webappsphp
Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload an
23RISK
open
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3308webappsphp
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals
23RISK
open
ReferênciaVexDay Proof
e107 < 0.7.8 - 'photograph' Arbitrary File Upload
CVE-2007-3429webappsphp
Unrestricted file upload vulnerability in signup.php in e107 0.7.8 and earlier, when photograph upload is enabled, allow
23RISK
open
ReferênciaVexDay Proof
CMS Ortus 1.13 - SQL Injection
CVE-2008-6282webappsphp
SQL injection vulnerability in engine/users/users_edit_pub.inc in CMS Ortus 1.13 and earlier allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Vivvo CMS 3.4 - 'index.php' Blind SQL Injection
CVE-2007-3939webappsphp
SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlie
23RISK
open
ReferênciaVexDay Proof
lustig.cms Beta 2.5 - 'forum.php?view' Remote File Inclusion
CVE-2007-5138webappsphp
PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Litespeed Web Server 3.2.3 - Source Code Disclosure
CVE-2007-5654remotemultiple
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
35RISK
open
ReferênciaVexDay Proof
phpFaber URLInn 2.0.5 - 'dir_ws' Remote File Inclusion
CVE-2007-5754webappsphp
PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5742webappsphp
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbit
23RISK
open
ReferênciaVexDay Proof
Intel 2200BG 802.11 - disassociation packet Kernel Memory Corruption
CVE-2007-0686doswindows
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of servi
23RISK
open
previouspage 164 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.