Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RISK
open
ReferênciaVexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
CVE-2008-1513webappsphp
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
CVE-2006-6716webappsphp
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RISK
open
ReferênciaVexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
CVE-2006-6722webappsphp
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RISK
open
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RISK
open
ReferênciaVexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
CVE-2008-6030webappsphp
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
CVE-2008-6031webappsphp
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Alphacontent 2.5.8 - 'id' SQL Injection
CVE-2008-1559webappsphp
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remo
23RISK
open
ReferênciaVexDay Proof
PostNuke 0.764 - Blind SQL Injection
CVE-2008-1591webappsphp
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabl
23RISK
open
ReferênciaVexDay Proof
Quick TFTP Server Pro 2.1 - Remote Overflow (SEH)
CVE-2008-1610remotewindows
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RISK
open
ReferênciaVexDay Proof
TFTP Server 1.4 - ST Buffer Overflow
CVE-2008-1611remotewindows
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RISK
open
ReferênciaVexDay Proof
Smoothflash - 'cid' SQL Injection
CVE-2008-1623webappsphp
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
LoudBlog 0.8.0a - 'ajax.php' SQL Injection
CVE-2008-6077webappsphp
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to exe
23RISK
open
ReferênciaVexDay Proof
KISGB (tmp_theme) 5.1.1 - Local File Inclusion
CVE-2008-1635webappsphp
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1650webappsphp
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1680webappsphp
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenanc
23RISK
open
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
ReferênciaVexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.5.1 - 'OVAS.exe' Overflow (SEH)
CVE-2008-1697remotewindows
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RISK
open
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow (PoC)
CVE-2008-1709doswindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RISK
open
ReferênciaVexDay Proof
FaScript FaPhoto 1.0 - 'show.php' SQL Injection
CVE-2008-1714webappsphp
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
KnowledgeQuest 2.6 - SQL Injection
CVE-2008-1726webappsphp
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
CVE-2008-6082doswindows
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISK
open
ReferênciaVexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
CVE-2006-6800webappsphp
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
CVE-2006-2682webappsphp
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
CVE-2006-2818webappsphp
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
CVE-2008-1732webappsphp
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
CVE-2008-1750webappsphp
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.