Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Gateway WebLaunch - ActiveX Remote Buffer Overflow
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISK
open
ReferênciaVexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
CVE-2008-0230webappsphp
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RISK
open
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0232webappsphp
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
CVE-2008-0310localsco
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RISK
open
ReferênciaVexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
CVE-2008-0332webappsphp
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
CVE-2008-0355webappsphp
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RISK
open
ReferênciaVexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0376webappsphp
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RISK
open
ReferênciaVexDay Proof
aflog 1.01 - Cross-Site Scripting / SQL Injection
CVE-2008-0398webappsphp
Cross-site scripting (XSS) vulnerability in aflog 1.01, and possibly earlier versions, allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
ibProArcade 3.3.0 - SQL Injection
CVE-2008-0770webappsphp
SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Mambo Component Comments 0.5.8.5g - SQL Injection
CVE-2008-0773webappsphp
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server 2000 - UPNP 'getdevicelist' Memory Leak Denial of Service
CVE-2005-3644doswindows
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 a
35RISK
open
ReferênciaVexDay Proof
phpQLAdmin 2.2.7 - Multiple Remote File Inclusions
CVE-2008-1067webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP c
28RISK
open
ReferênciaVexDay Proof
GROUP-E 1.6.41 - 'head_auth.php' Remote File Inclusion
CVE-2008-1074webappsphp
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitr
35RISK
open
ReferênciaVexDay Proof
Microsoft Windows - GDI (CreateDIBPatternBrushPt) Heap Overflow (PoC)
CVE-2008-1083HIGHdoswindows
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RISK
open
ReferênciaVexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
CVE-2006-0179doshardware
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RISK
open
ReferênciaVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
CVE-2006-0476remotewindows
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISK
open
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1229webappsjsp
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RISK
open
ReferênciaVexDay Proof
BM Classifieds 20080409 - Multiple SQL Injections
CVE-2008-1272webappsphp
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
CVE-2008-1295webappsphp
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RISK
open
ReferênciaVexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
CVE-2006-0537remotewindows
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RISK
open
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1110webappsphp
Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HT
23RISK
open
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1111webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RISK
open
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1112webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RISK
open
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1346webappsphp
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1348webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
CVE-2006-1371webappsphp
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RISK
open
ReferênciaVexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1668webappsphp
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows
23RISK
open
ReferênciaVexDay Proof
Clansys 1.1 (showid) - SQL Injection
CVE-2006-1708webappsphp
SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
previouspage 178 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.