Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
yahoo answers - 'id' SQL Injection
CVE-2008-5490webappsphp
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
CVE-2008-5491webappsphp
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
CVE-2008-5492doswindows
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISK
open
ReferênciaVexDay Proof
PHPstore Wholesale - 'id' SQL Injection
CVE-2008-5493webappsphp
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Contact Info 1.0 - SQL Injection
CVE-2008-5494webappsphp
SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
PozScripts Business Directory Script - 'cid' SQL Injection
CVE-2008-5496webappsphp
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Apache Geronimo 2.1.3 - Multiple Directory Traversal Vulnerabilities
CVE-2008-5518remotemultiple
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1
35RISK
open
ReferênciaVexDay Proof
postecards - SQL Injection / File Disclosure
CVE-2008-5559webappsasp
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
postecards - SQL Injection / File Disclosure
CVE-2008-5560webappsasp
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Netref 4.0 - Multiple SQL Injections
CVE-2008-5561webappsphp
SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
ReferênciaVexDay Proof
DL PayCart 1.34 - Admin Password Changing
CVE-2008-5565webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Bonza Cart 1.10 - Admin Password Changing
CVE-2008-5567webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
CVE-2009-0380webappsphp
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and
23RISK
open
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Authentication Bypass
CVE-2008-5571webappsasp
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Trend Micro OfficeScan - ObjRemoveCtrl ActiveX Control Buffer Overflow
CVE-2008-3364remotewindows
Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeS
35RISK
open
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
CVE-2008-5572webappsasp
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RISK
open
ReferênciaVexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
CVE-2009-0394webappsphp
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5578webappsphp
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Nukedit 4.9.x - Remote Create Admin
CVE-2008-5582webappsphp
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
lcxbbportal 0.1 alpha 2 - Remote File Inclusion
CVE-2008-5585webappsphp
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
CVE-2009-0395webappsphp
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
RankEm - 'siteID' SQL Injection
CVE-2008-5588webappsasp
SQL injection vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
GOM Player 2.1.6.3499 - 'GomWeb3.dll 1.0.0.12' Remote Overflow
CVE-2007-5779remotewindows
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RISK
open
ReferênciaVexDay Proof
Rankem - Authentication Bypass
CVE-2008-5589webappsasp
SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Product Sale Framework 0.1b - SQL Injection
CVE-2008-5590webappsphp
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RISK
open
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5591webappsphp
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
Elecard AVC HD player - '.m3u' / '.xpl' Local Stack Overflow (PoC)
CVE-2009-0443doswindows
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an
23RISK
open
ReferênciaVexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
CVE-2008-5595webappsasp
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.doc' Malformed Pointers Denial of Service
CVE-2007-1347doswindows
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remot
35RISK
open
ReferênciaVexDay Proof
Ikon ADManager 2.1 - Remote Database Disclosure
CVE-2008-5596webappsasp
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which a
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.