Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,184cataloged exploits
37,029CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
Pligg CMS 9.9.0 - Remote Code Execution
CVE-2008-7091webappsphp30 Jul 2008
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-6968webappsphp30 Jul 2008
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
Unreal Tournament 3 - Memory Corruption (Denial of Service)
CVE-2008-3409dosmultiple30 Jul 2008
Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory
28RISK
open
Exploit-DBVexDay Proof
MJGUEST 6.8 - 'Guestbook.js.php' Cross-Site Scripting
CVE-2008-3404webappsphp30 Jul 2008
Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
PozScripts Classified Ads Script - 'cid' SQL Injection
CVE-2008-3672webappsphp30 Jul 2008
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
e107 Plugin BLOG Engine 2.2 - Blind SQL Injection
CVE-2008-6438webappsphp29 Jul 2008
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open
Exploit-DBVexDay Proof
Eyeball MessengerSDK 'CoVideoWindow.ocx' 5.0.907 - ActiveX Control Remote Buffer Overflow
CVE-2008-3430remotewindows29 Jul 2008
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as
23RISK
open
Exploit-DBVexDay Proof
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB)
CVE-2007-2586remotehardware29 Jul 2008
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers
28RISK
open
Exploit-DBVexDay Proof
Web Wiz Forum 9.5 - 'admin_category_details.asp?mode' Cross-Site Scripting
CVE-2008-3391webappsasp28 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Jamroom 3.3.8 - Cookie Authentication Bypass
CVE-2008-3375webappsphp28 Jul 2008
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authent
23RISK
open
Exploit-DBVexDay Proof
Web Wiz Forum 9.5 - 'admin_group_details.asp?mode' Cross-Site Scripting
CVE-2008-3391webappsasp28 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Owl Intranet Engine 0.95 - 'register.php' Cross-Site Scripting
CVE-2008-3100webappsphp28 Jul 2008
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgeb
23RISK
open
Exploit-DBVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-4194remotemultiple25 Jul 2008
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
EZContents - 'minicalendar.php' Remote File Inclusion
CVE-2008-3575webappsphp25 Jul 2008
PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Microsoft Access - 'Snapview.ocx 10.0.5529.0' ActiveX Remote File Download
CVE-2008-2463remotewindows24 Jul 2008
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snaps
50RISK
open
Exploit-DBVexDay Proof
AtomPhotoBlog 1.15 - 'atomPhotoBlog.php' SQL Injection
CVE-2008-3351webappsphp24 Jul 2008
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RISK
open
Exploit-DBVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-4194remotemultiple24 Jul 2008
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
EMC Centera Universal Access 4.0_4735.p4 - 'Username' SQL Injection
CVE-2008-3370webappsphp23 Jul 2008
SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
CVE-2008-4194remotemultiple23 Jul 2008
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.8 - '/tracking/toolaccess_details.php?toolId' Cross-Site Scripting
CVE-2008-3315webappsphp22 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
Pre Survey Generator - 'default.asp' SQL Injection
CVE-2008-3310webappsasp22 Jul 2008
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.8 - '/tracking/courseLog.php?view' Cross-Site Scripting
CVE-2008-3315webappsphp22 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.8 - 'learnPath/calendar/myagenda.php' Query String Cross-Site Scripting
CVE-2008-3315webappsphp22 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3306webappsphp22 Jul 2008
SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.8 - 'user/user.php' Query String Cross-Site Scripting
CVE-2008-3315webappsphp22 Jul 2008
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
AlphAdmin CMS 1.0.5_03 - 'aa_login' Cookie Authentication Bypass
CVE-2008-3300webappsphp21 Jul 2008
AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa
23RISK
open
Exploit-DBVexDay Proof
PHPKF - 'forum_duzen.php' SQL Injection
CVE-2008-6443webappsphp21 Jul 2008
SQL injection vulnerability in forum_duzen.php in phpKF allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
IntelliTamper 2.07 - '.map' Local Arbitrary Code Execution (2)
CVE-2008-5755localwindows21 Jul 2008
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP f
23RISK
open
Exploit-DBVexDay Proof
ZDaemon 1.8 - Null Pointer Remote Denial of Service
CVE-2008-3314dosmultiple21 Jul 2008
ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 com
23RISK
open
Exploit-DBVexDay Proof
Asterisk 1.6 IAX - 'POKE' Requests Remote Denial of Service
CVE-2008-3263doslinux21 Jul 2008
The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business
28RISK
open
previouspage 298 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.