Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Soulseek 157 NS - Remote Buffer Overflow (SEH)
CVE-2009-1830remotewindows
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RISK
open
ReferênciaVexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
CVE-2008-5215webappsphp
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RISK
open
ReferênciaVexDay Proof
AJ Article 1.0 - 'featured_article.php' SQL Injection
CVE-2008-5213webappsphp
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
CVE-2008-5220webappsphp
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RISK
open
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow (PoC)
CVE-2009-1831doswindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open
ReferênciaVexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
CVE-2008-5002remotewindows
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISK
open
ReferênciaVexDay Proof
Cisco Phone 7940 - Remote Denial of Service
CVE-2007-5583doshardware
Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" response
23RISK
open
ReferênciaVexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
CVE-2008-5223webappsphp
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities
CVE-2008-7172webappsphp
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote
23RISK
open
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow
CVE-2009-1831localwindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISK
open
ReferênciaVexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
CVE-2008-5265webappsphp
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RISK
open
ReferênciaVexDay Proof
Experts 1.0.0 - 'answer.php' SQL Injection
CVE-2008-5267webappsphp
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
ASPPortal Free Version - 'Topic_Id' SQL Injection
CVE-2008-5268webappsasp
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
pSys 0.7.0.a - 'shownews' SQL Injection
CVE-2008-5269webappsphp
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
Yuhhu 2008 SuperStar - 'board' SQL Injection
CVE-2008-5270webappsphp
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7209webappsphp
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RISK
open
ReferênciaVexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5271webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
CVE-2006-4207webappsphp
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Todd Woolums ASP News Management 2.2 - SQL Injection
CVE-2008-5273webappsasp
SQL injection vulnerability in viewnews.asp in Todd Woolums ASP News Management 2.2 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection
CVE-2008-5289webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
CVE-2008-5289webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
CVE-2020-14425localwindows
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RISK
open
ReferênciaVexDay Proof
phpBB All Topics Mod 1.5.0 - 'start' SQL Injection
CVE-2006-4367webappsphp
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote att
23RISK
open
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
CVE-2008-5290webappsphp
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to in
23RISK
open
ReferênciaVexDay Proof
Booby 1.0.1 - Multiple Remote File Inclusions
CVE-2008-2645webappsphp
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbi
35RISK
open
ReferênciaVexDay Proof
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
CVE-2007-5627webappsphp
PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
VideoGirls BiZ - Blind SQL Injection
CVE-2008-5292webappsphp
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Joomla! Component AgoraGroup 0.3.5.3 - Blind SQL Injection
CVE-2009-1848webappsphp
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows
23RISK
open
ReferênciaVexDay Proof
WebStudio eHotel - Blind SQL Injection
CVE-2008-5293webappsphp
SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands v
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.