Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Sige 0.1 - 'sige_init.php' Remote File Inclusion
CVE-2007-5781webappsphp
PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PH
35RISK
open
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final (Simple Forum 3.1d) - Change Admin Password
CVE-2008-5308webappsphp
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_lurm_constructor 0.6b - Remote File Inclusion
CVE-2006-4372webappsphp
PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constr
23RISK
open
ReferênciaVexDay Proof
Netartmedia Real Estate Portal 1.2 - 'ad_id' SQL Injection
CVE-2008-5309webappsphp
SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
CVE-2006-4373webappsphp
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RISK
open
ReferênciaVexDay Proof
e107 < 0.7.13 - 'usersettings.php' Blind SQL Injection
CVE-2008-5320webappsphp
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute
23RISK
open
ReferênciaVexDay Proof
PeopleAggregator 1.2pre6-release-53 - Multiple Remote File Inclusions
CVE-2007-5631webappsphp
Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow
35RISK
open
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-5322webappsphp
Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, wh
23RISK
open
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-5323webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
RiotPix 0.61 - Authentication Bypass
CVE-2009-0109webappsphp
SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Apple QuickTime 7.2/7.3 (OSX/Windows) - RSTP Response Universal
CVE-2002-0252remotemultiple
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RISK
open
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote File Inclusion / SQL Injection
CVE-2008-5334webappsphp
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5642webappsphp
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to incl
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion 7.00.1 - 'messages.php' SQL Injection
CVE-2008-5335webappsphp
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
WebStudio CMS - Blind SQL Injection
CVE-2008-5336webappsphp
SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Ultra Shareware Office Control - ActiveX Control Remote Buffer Overflow
CVE-2008-3878remotewindows
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RISK
open
ReferênciaVexDay Proof
CUPS < 1.3.8-4 - Local Privilege Escalation
CVE-2008-5377localmultiple
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log tempo
23RISK
open
ReferênciaVexDay Proof
Joomla! Component mp3 allopass 1.0 - Remote File Inclusion
CVE-2007-5412webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joo
35RISK
open
ReferênciaVexDay Proof
scWiki 1.0 Beta 2 - 'common.php?pathdot' Remote File Inclusion
CVE-2007-5843webappsphp
PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute a
35RISK
open
ReferênciaVexDay Proof
Debian - Symlink In Login Arbitrary File Ownership
CVE-2008-5394locallinux
/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utm
23RISK
open
ReferênciaVexDay Proof
vicFTP 5.0 - 'LIST' Remote Denial of Service
CVE-2008-6829doswindows
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RISK
open
ReferênciaVexDay Proof
Xerox Phaser 8400 - Remote Reboot (Denial of Service)
CVE-2008-3571doshardware
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900
35RISK
open
ReferênciaVexDay Proof
Cain & Abel 4.9.23 - '.rdp' Buffer Overflow (PoC)
CVE-2008-5405doswindows
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISK
open
ReferênciaVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0251webappsphp
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2009-0259doswindows
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) an
23RISK
open
ReferênciaVexDay Proof
Luxbum 0.5.5/stable - Authentication Bypass
CVE-2009-1913webappsphp
SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authenticatio
23RISK
open
ReferênciaVexDay Proof
Cain & Abel 4.9.24 - '.rdp' Local Stack Overflow
CVE-2008-5405localwindows
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISK
open
ReferênciaVexDay Proof
Flax Article Manager 1.1 - 'cat_id' SQL Injection
CVE-2009-0284webappsphp
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
CVE-2009-1947webappsphp
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Text Link Sales - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-5486webappsphp
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQ
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.