Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,966cataloged exploits
35,269CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
CVE-2008-6471webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2014-6030
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Blogator-script 0.95 - Change User Password
CVE-2008-6473webappsphp
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RISK
open
ReferênciaVexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
CVE-2008-6475webappsphp
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RISK
open
ReferênciaVexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
CVE-2008-6481webappsphp
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
CVE-2008-6482webappsphp
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RISK
open
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
CVE-2006-3400doswindows
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISK
open
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
CVE-2008-6487webappsasp
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
CVE-2008-6488webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
CVE-2008-6490webappsphp
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RISK
open
ReferênciaVexDay Proof
Easy News Content Management - Database Disclosure
CVE-2008-6493webappsasp
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RISK
open
ReferênciaVexDay Proof
ASP User Engine .NET - Remote Database Disclosure
CVE-2008-6494webappsphp
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open
ReferênciaVexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
CVE-2008-6499remotewindows
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RISK
open
ReferênciaVexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
CVE-2008-6513webappsphp
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RISK
open
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6523webappsphp
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RISK
open
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
CVE-2008-6528remotewindows
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RISK
open
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open
ReferênciaVexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
CVE-2008-6748remotewindows
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RISK
open
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6771webappsphp
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RISK
open
ReferênciaVexDay Proof
SFS EZ Affiliate - 'cat_id' SQL Injection
CVE-2008-6780webappsphp
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to exec
23RISK
open
Referência
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote attackers to inject arbitr
23RISK
open
ReferênciaVexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
CVE-2008-6781webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
CVE-2008-6781webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
SFS EZ Home Business Directory - 'cat_id' SQL Injection
CVE-2008-6783webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attacke
23RISK
open
previouspage 341 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.