Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,313cataloged exploits
34,834CVEs with public exploitation
24,695lab-tested
21,797 exploits
ReferênciaVexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
CVE-2006-6849webappsphp
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RISK
open
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4933webappsphp
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RISK
open
ReferênciaVexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5055webappsphp
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6396webappsphp
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RISK
open
ReferênciaVexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
CVE-2008-0278webappsphp
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
CVE-2008-2938remotemultiple
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISK
open
Referência
CVE-2017-15081
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RISK
open
Referência
CVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISK
open
Referência
CVE-2010-5057
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Referência
CVE-2009-3064
Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
CubeCart 3.0.6 - Remote Command Execution
CVE-2006-0064webappsphp
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute ar
23RISK
open
Referência
CVE-2009-3824
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attacker
23RISK
open
Referência
CVE-2010-2905
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers
23RISK
open
ReferênciaVexDay Proof
inertianews 0.02b - 'inertianews_main.php' Remote File Inclusion
CVE-2006-6726webappsphp
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to exec
23RISK
open
Referência
CVE-2007-1580
FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive
23RISK
open
Referência
CVE-2019-18859
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
23RISK
open
ReferênciaVexDay Proof
EQdkp 1.3.1 - 'Referer Spoof' Remote Database Backup
CVE-2007-0760webappsphp
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an adm
23RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6501webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable
23RISK
open
ReferênciaVexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
CVE-2008-0724webappsphp
The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext
23RISK
open
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2534webappsphp
Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution
CVE-2008-2950locallinux
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not
28RISK
open
ReferênciaVexDay Proof
CMS Mini 0.2.2 - Multiple Local File Inclusions
CVE-2008-2961webappsphp
Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrar
23RISK
open
Referência
CVE-2012-4871
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.
23RISK
open
Referência
CVE-2010-2906
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remot
23RISK
open
Referência
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Referência
CVE-2018-6563
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RISK
open
Referência
CVE-2010-4918
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote att
23RISK
open
Referência
CVE-2010-4918
PHP remote file inclusion vulnerability in iJoomla Magazine (com_magazine) component 3.0.1 for Joomla! allows remote att
23RISK
open
Referência
CVE-2010-0966
PHP remote file inclusion vulnerability in inc/config.php in deV!L`z Clanportal (DZCP) 1.5.2, when register_globals is e
23RISK
open
Referência
CVE-2012-1912
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers
23RISK
open
previouspage 299 / 727next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.