Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' Blind SQL Injection
CVE-2008-4185webappsphp
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Harlandscripts Pro Traffic One - 'mypage.php' SQL Injection
CVE-2008-6213webappsphp
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
CVE-2008-6220webappsphp
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RISK
open
ReferênciaVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1282webappsphp
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Sitellite CMS 4.2.12 - '559668.php' Remote File Inclusion
CVE-2007-3228webappsphp
PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CM
35RISK
open
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4206webappsphp
PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is e
23RISK
open
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RISK
open
ReferênciaVexDay Proof
CJ Ultra Plus 1.0.4 - Cookie SQL Injection
CVE-2008-4241webappsphp
SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server - Code Execution (PoC) (MS08-067)
CVE-2008-4250CRITICALunder attackdoswindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server - Code Execution (MS08-067)
CVE-2008-4250CRITICALunder attackremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server - Universal Code Execution (MS08-067)
CVE-2008-4250CRITICALunder attackremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
ReferênciaVexDay Proof
smcFanControl 2.1.2 (OSX) - Multiple Buffer Overflow Vulnerabilities (PoC)
CVE-2008-6252dososx
Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and g
23RISK
open
ReferênciaVexDay Proof
OpenASP 3.0 - Blind SQL Injection
CVE-2008-6257webappsasp
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Cyberfolio 7.12.2 - 'theme' Local File Inclusion
CVE-2008-6265webappsphp
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to inclu
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
CVE-2008-4250CRITICALunder attackremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.zip' Denial of Service
CVE-2008-4323doswindows
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RISK
open
ReferênciaVexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
CVE-2008-4331webappsphp
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
PHP infoBoard 7 - Plus Insecure Cookie Handling
CVE-2008-4334webappsphp
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in
23RISK
open
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow
CVE-2006-6251localwindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Blind SQL Injection
CVE-2008-4335webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6293webappsphp
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RISK
open
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4335webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4336webappsphp
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RISK
open
ReferênciaVexDay Proof
TFTP Server for Windows 1.4 - ST Remote BSS Overflow
CVE-2008-2161remotewindows
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execut
50RISK
open
ReferênciaVexDay Proof
pNews 2.03 - 'newsid' SQL Injection
CVE-2008-4347webappsphp
SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4346webappsphp
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX - 'mount_smbfs' Local Stack Buffer Overflow
CVE-2007-3876localosx
Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long
23RISK
open
ReferênciaVexDay Proof
WM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1327doswindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.