Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
C-News 1.0.1 - 'path' Remote File Inclusion
CVE-2006-4629webappsphp
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
MySpeach 3.0.2 - 'my_ms[root]' Remote File Inclusion
CVE-2006-4630webappsphp
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals
23RISK
open
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4633webappsphp
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISK
open
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
CVE-2006-6237webappsphp
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISK
open
ReferênciaVexDay Proof
Magic News Pro 1.0.3 - 'script_path' Remote File Inclusion
CVE-2006-4823webappsphp
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier
23RISK
open
ReferênciaVexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
CVE-2006-6349webappsasp
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Mambo Component Shambo2 - 'itemID' SQL Injection
CVE-2008-0606webappsphp
SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote atta
23RISK
open
ReferênciaVexDay Proof
Ipswitch WS_FTP Server with SSH 6.1.0.0 - Remote Buffer Overflow (PoC)
CVE-2008-0590doswindows
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of servic
28RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
CVE-2008-0600locallinux
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RISK
open
ReferênciaVexDay Proof
All Club CMS 0.0.2 - 'index.php' SQL Injection
CVE-2008-0601webappsphp
SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
All Club CMS 0.0.1f - 'index.php' Local File Inclusion
CVE-2008-0602webappsphp
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
Mambo Component 'com_awesom' 0.3.2 - 'listid' SQL Injection
CVE-2008-0603webappsphp
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows
23RISK
open
ReferênciaVexDay Proof
RMSOFT Gallery System 2.0 - 'id' SQL Injection
CVE-2008-0611webappsphp
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers
23RISK
open
ReferênciaVexDay Proof
phpunity.postcard - 'gallery_path' Remote File Inclusion
CVE-2006-4869webappsphp
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
EPNadmin 0.7 - 'constantes.inc.php' Remote File Inclusion
CVE-2006-5555webappsphp
PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'swmodify' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'swpackage' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISK
open
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RISK
open
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0134webappsphp
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the
28RISK
open
ReferênciaVexDay Proof
Aratix 0.2.2b11 - '/inc/init.inc.php' Remote File Inclusion
CVE-2007-0135webappsphp
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
L2J Statistik Script 0.09 - 'index.php' Local File Inclusion
CVE-2007-0173webappsphp
Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enable
23RISK
open
ReferênciaVexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0225webappsasp
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
Astanda Directory Project 1.2 - 'link_id' SQL Injection
CVE-2008-0649webappsphp
SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RISK
open
ReferênciaVexDay Proof
Mihalism Multi Host Download - 'Username' Blind SQL Injection
CVE-2008-0714webappsphp
SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL command
23RISK
open
previouspage 173 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.