Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
22,103 exploits
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6788webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RISK
open
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
CVE-2008-6789webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
CVE-2008-6791doswindows
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RISK
open
ReferênciaVexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
CVE-2008-6795webappsphp
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'id_kat' SQL Injection
CVE-2008-6813webappsphp
SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Lanifex DMO 2.3b - '_incMgr' Remote File Inclusion
CVE-2006-4604webappsphp
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Be
23RISK
open
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
CVE-2008-6814webappsphp
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RISK
open
ReferênciaVexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2008-6824remotehardware
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4605webappsphp
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4606webappsphp
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
CVE-2006-4610webappsphp
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RISK
open
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
CVE-2008-6841webappsphp
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
CVE-2008-6842webappsphp
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6848webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6849webappsphp
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
PHPLD 3.3 - Blind SQL Injection
CVE-2008-6851webappsphp
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_qu
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
CVE-2008-6852webappsphp
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
CVE-2008-6853webappsphp
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RISK
open
ReferênciaVexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
CVE-2008-6856webappsphp
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RISK
open
ReferênciaVexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
CVE-2008-6857webappsphp
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RISK
open
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
CVE-2008-6860webappsphp
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open
Referência
CVE-2008-6887
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Getleft 1.2 - Remote Buffer Overflow (PoC)
CVE-2008-6897dosmultiple
Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of servic
23RISK
open
Referência
CVE-2008-6898
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open
ReferênciaVexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
CVE-2008-6898remotewindows
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISK
open
ReferênciaVexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RISK
open
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
CVE-2008-6902webappsphp
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RISK
open
ReferênciaVexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RISK
open
previouspage 347 / 737next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.