Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,166 exploits
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2873webappsphp
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RISK
open
ReferênciaVexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
CVE-2006-5078webappsphp
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
CVE-2006-5079webappsphp
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
CVE-2009-0325webappsphp
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RISK
open
ReferênciaVexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
CVE-2009-0639webappsphp
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RISK
open
Referência
CVE-2014-5520
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2022-40797
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.
48RISK
open
Referência
CVE-2014-3871
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RISK
open
Referência
CVE-2020-5147
SonicWall NetExtender Windows client vulnerable to unquoted service path vulnerability, this allows a local attacker to
23RISK
open
Referência
CVE-2012-4998
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script
23RISK
open
Referência
CVE-2008-0843
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISK
open
Referência
CVE-2008-0843
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RISK
open
Referência
CVE-2016-3652
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RISK
open
ReferênciaVexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
CVE-2006-1252webappsphp
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2009-4447
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ
23RISK
open
ReferênciaVexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
CVE-2007-5017remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RISK
open
Referência
CVE-2016-1000124
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RISK
open
Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISK
open
Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RISK
open
Referência
CVE-2011-4674
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows rem
23RISK
open
Referência
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RISK
open
Referência
CVE-2023-34723
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RISK
open
Referência
CVE-2010-1653
Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! a
43RISK
open
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - 'teams.php' SQL Injection
CVE-2008-2890webappsphp
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers
23RISK
open
Referência
CVE-2016-4313
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Calendar Script 1.1 - Insecure Cookie Handling
CVE-2008-5738webappsphp
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by s
23RISK
open
ReferênciaVexDay Proof
PHPAuctionSystem - Insecure Cookie Handling
CVE-2009-0108webappsphp
PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m
23RISK
open
Referência
CVE-2010-2622
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
CVE-2006-6599webappsphp
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RISK
open
ReferênciaVexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
CVE-2007-6184webappsphp
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RISK
open
previouspage 364 / 739next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.