Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Enthrallweb emates 1.0 - 'newsdetail.asp' SQL Injection
CVE-2006-6806webappsasp
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
CVE-2008-1758webappsphp
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Akamai Download Manager < 2.2.3.7 - ActiveX Remote Download
CVE-2008-1770remotewindows
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force
28RISK
open
ReferênciaVexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
CVE-2008-6115webappsphp
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Sabros.us 1.75 - 'thumbnails.php' Remote File Disclosure
CVE-2008-1799webappsphp
Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files vi
23RISK
open
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
CVE-2008-1802doslinux
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RISK
open
ReferênciaVexDay Proof
BosClassifieds 3.0 - 'index.php' SQL Injection
CVE-2008-1838webappsphp
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
ForumApp 3.3 - Remote Database Disclosure
CVE-2008-6147webappsasp
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISK
open
ReferênciaVexDay Proof
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
CVE-2006-6811doslinux
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
28RISK
open
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
CVE-2008-7181webappsphp
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RISK
open
ReferênciaVexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2167webappsphp
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RISK
open
ReferênciaVexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
CVE-2019-14748webappsphp
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RISK
open
ReferênciaVexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
CVE-2019-14750webappsphp
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RISK
open
ReferênciaVexDay Proof
724CMS 4.01 Enterprise - 'index.php' SQL Injection
CVE-2008-1858webappsphp
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1859webappsphp
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
CVE-2008-1867webappsphp
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
PIGMy-SQL 1.4.1 - 'getdata.php' Blind SQL Injection
CVE-2008-1870webappsphp
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
XPOZE Pro 3.05 - 'reed' SQL Injection
CVE-2008-1874webappsphp
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to
23RISK
open
ReferênciaVexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
CVE-2008-1878doslinux
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RISK
open
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
CVE-2008-1881localwindows
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
Joomla! Component xsstream-dm 0.01b - SQL Injection
CVE-2008-2454webappsphp
SQL injection vulnerability in the xsstream-dm (com_xsstream-dm) component 0.01 Beta for Joomla! allows remote attackers
23RISK
open
ReferênciaVexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
CVE-2008-6197webappsphp
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1885remotewindows
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficien
23RISK
open
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RISK
open
ReferênciaVexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1896webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
CVE-2008-6210webappsphp
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-15107CRITICALunder attackransomwareremotelinux
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RISK
open
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.