Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1124webappsphp
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RISK
open
ReferênciaVexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1125webappsphp
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read
23RISK
open
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RISK
open
ReferênciaVexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
CVE-2006-0852webappsphp
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
vuBB 0.2 Final - 'cookie' SQL Injection
CVE-2006-0962webappsphp
SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter
23RISK
open
ReferênciaVexDay Proof
Lansuite 2.1.0 Beta - 'fid' SQL Injection
CVE-2006-1001webappsphp
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote
23RISK
open
ReferênciaVexDay Proof
crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow
CVE-2006-1236remotelinux
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RISK
open
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
CVE-2006-1540doswindows
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RISK
open
ReferênciaVexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
CVE-2006-1542locallinux
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RISK
open
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1778webappsphp
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
CVE-2006-1781webappsphp
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
CVE-2006-1784webappsphp
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RISK
open
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1832webappscgi
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RISK
open
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1837webappsphp
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Internet PhotoShow 1.3 - 'page' Remote File Inclusion
CVE-2006-1919webappsphp
PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
ACal 2.2.6 - 'day.php' Remote File Inclusion
CVE-2006-2261webappsphp
PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code v
23RISK
open
ReferênciaVexDay Proof
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
CVE-2006-2361webappsphp
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as us
23RISK
open
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
CVE-2006-2363webappsphp
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
metajour 2.1 - 'system_path' Remote File Inclusion
CVE-2006-2768webappsphp
PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
CVE-2006-2802doslinux
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RISK
open
ReferênciaVexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
CVE-2006-2834webappsphp
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2845webappsphp
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code vi
23RISK
open
ReferênciaVexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
CVE-2006-2848webappsasp
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RISK
open
ReferênciaVexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
CVE-2006-3162webappsphp
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
The Bible Portal Project 2.12 - 'destination' File Inclusion
CVE-2006-3177webappsphp
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
CVE-2006-2864webappsphp
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RISK
open
ReferênciaVexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
CVE-2006-2962webappsphp
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RISK
open
ReferênciaVexDay Proof
Enterprise Payroll Systems 1.1 - 'footer' Remote File Inclusion
CVE-2006-2982webappsphp
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier all
23RISK
open
previouspage 179 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.