Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
CVE-2007-4983remotewindows
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RISK
open
ReferênciaVexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RISK
open
ReferênciaVexDay Proof
C6 Messenger - ActiveX Remote Download and Execute
CVE-2008-2551remotewindows
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force
50RISK
open
ReferênciaVexDay Proof
WordPress Plugin BackUpWordPress 0.4.2b - Remote File Inclusion
CVE-2007-5800webappsphp
Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow
35RISK
open
ReferênciaVexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
CVE-2008-5004webappsphp
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
CVE-2008-6808webappsphp
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Ace-FTP Client 1.24a - Remote Buffer Overflow (PoC)
CVE-2007-3161doswindows
Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long re
23RISK
open
ReferênciaVexDay Proof
GeometriX Download Portal - 'down_indir.asp?id' SQL Injection
CVE-2007-3188webappsasp
SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
MaxCMS 2.0 - '/inc/ajax.asp' SQL Injection
CVE-2009-1764webappsasp
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
FTP Now 2.6 Server - Response Remote Crash (PoC)
CVE-2008-5045doswindows
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to caus
23RISK
open
ReferênciaVexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2007-5365dosmultiple
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RISK
open
ReferênciaVexDay Proof
LightOpenCMS 0.1 - 'id' SQL Injection
CVE-2009-1766webappsphp
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
CVE-2009-3342webappsphp
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RISK
open
ReferênciaVexDay Proof
Real Player - 'rmoc3260.dll' ActiveX Control Remote Code Execution
CVE-2008-1309remotewindows
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RISK
open
ReferênciaVexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
CVE-2008-5051webappsphp
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
DFD Cart 1.1 - Multiple Remote File Inclusions
CVE-2007-5098webappsphp
Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allo
35RISK
open
ReferênciaVexDay Proof
FeedMon 2.7.0.0 - outline Tag Buffer Overflow (PoC)
CVE-2009-0546doswindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RISK
open
ReferênciaVexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
CVE-2008-5054webappsphp
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RISK
open
ReferênciaVexDay Proof
Microsoft SQL Server - Distributed Management Objects 'sqldmo.dll' Buffer Overflow (PoC)
CVE-2007-4814doswindows
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RISK
open
ReferênciaVexDay Proof
WebDesktop 0.1 - Remote File Inclusion
CVE-2007-5388webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP cod
35RISK
open
ReferênciaVexDay Proof
CuteNews 1.1.1 - 'html.php' Remote Code Execution
CVE-2008-4557webappsphp
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute
35RISK
open
ReferênciaVexDay Proof
PicoFlat CMS 0.4.14 - 'index.php' Remote File Inclusion
CVE-2007-5390webappsphp
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
CVE-2008-6842webappsphp
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
PHPSlash 0.8.1.1 - Remote Code Execution
CVE-2009-0517webappsphp
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary P
35RISK
open
ReferênciaVexDay Proof
VIDEOSCRIPT.us - Authentication Bypass
CVE-2009-1804webappsphp
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
CVE-2008-5066webappsphp
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RISK
open
ReferênciaVexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-5009webappsphp
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RISK
open
ReferênciaVexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
CVE-2007-5423webappsphp
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.