Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
phpMyAdmin - '/scripts/setup.php' PHP Code Injection
CVE-2009-1151CRITICALunder attackwebappsphp
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISK
open
ReferênciaVexDay Proof
Particle Gallery 1.0.1 - SQL Injection
CVE-2007-3065webappsphp
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RISK
open
ReferênciaVexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
CVE-2008-4093webappsphp
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - 'WRITE_ANDX' SMB Command Handling Kernel Denial of Service (Metasploit)
CVE-2008-4114doswindows
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RISK
open
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RISK
open
ReferênciaVexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
CVE-2008-6143webappsphp
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RISK
open
ReferênciaVexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.5.5 - Remote File Inclusion
CVE-2008-4141webappsphp
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
addalink 4 - 'category_id' SQL Injection
CVE-2008-4145webappsphp
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled
23RISK
open
ReferênciaVexDay Proof
Sepcity Lawyer Portal - SQL Injection
CVE-2008-6152webappsasp
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Diesel Joke Site - 'picture_category.php' SQL Injection
CVE-2008-4150webappsphp
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
CYASK 3.x - 'neturl' Local File Disclosure
CVE-2008-4151webappsphp
Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
CustomCMS 4.0 - 'print.php' SQL Injection
CVE-2008-4156webappsphp
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow
23RISK
open
ReferênciaVexDay Proof
eMeeting Online Dating Software 5.2 - SQL Injection
CVE-2007-3609webappsphp
Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Zanfi CMS lite / Jaw Portal free - 'page' SQL Injection
CVE-2008-4159webappsphp
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
iScripts EasyIndex - 'produid' SQL Injection
CVE-2008-4169webappsphp
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
AdMan 1.1.20070907 - 'campaignId' SQL Injection
CVE-2008-6156webappsphp
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbit
23RISK
open
ReferênciaVexDay Proof
Amaya 11.1 - W3C Editor/Browser 'defer' Remote Stack Overflow
CVE-2009-1209remotewindows
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RISK
open
ReferênciaVexDay Proof
ProArcadeScript 1.3 - 'random' SQL Injection
CVE-2008-4173webappsphp
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran
23RISK
open
ReferênciaVexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
CVE-2008-4177webappsphp
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
PHPVID 0.9.9 - 'categories_type.php' SQL Injection
CVE-2007-3610webappsphp
SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RWCards 3.0.11 - Local File Inclusion
CVE-2008-6172webappsphp
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RISK
open
ReferênciaVexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
CVE-2009-1404webappsphp
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine newdownlinebuilder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine paidversion - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Integramod 1.4.x - Insecure Directory Download Database
CVE-2008-4183webappsphp
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open
ReferênciaVexDay Proof
SerWeb 0.9.4 - 'load_lang.php' Remote File Inclusion
CVE-2007-3358webappsphp
PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to exe
35RISK
open
ReferênciaVexDay Proof
TotalCalendar 2.4 - 'Include' Local File Inclusion
CVE-2009-1406webappsphp
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
CVE-2007-3068localwindows
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.