Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
22,175 exploits
ReferênciaVexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
CVE-2008-4591webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
23RISK
open
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-0147webappsphp
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple
28RISK
open
ReferênciaVexDay Proof
The Gemini Portal 4.7 - 'lang' Remote File Inclusion
CVE-2008-4720webappsphp
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ClamAV < 0.94.2 - JPEG Parsing Recursive Stack Overflow (PoC)
CVE-2008-5314dosmultiple
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
CVE-2008-5787webappsphp
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RISK
open
Referência
CVE-2009-4423
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Referência
CVE-2010-1923
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remot
23RISK
open
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4604webappsphp
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL command
23RISK
open
Referência
CVE-2014-3977
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on
23RISK
open
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
Referência
CVE-2014-3977
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on
23RISK
open
ReferênciaVexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISK
open
Referência
CVE-2017-17570
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o
23RISK
open
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISK
open
ReferênciaVexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
CVE-2008-4626webappsphp
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RISK
open
ReferênciaVexDay Proof
WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection
CVE-2008-4627webappsphp
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
CVE-2008-4628webappsphp
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4643webappsphp
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RISK
open
ReferênciaVexDay Proof
Dart Communications PowerTCP FTP module - Remote Buffer Overflow
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RISK
open
ReferênciaVexDay Proof
PowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RISK
open
ReferênciaVexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
CVE-2008-4675webappsphp
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
CVE-2008-4682dosmultiple
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
23RISK
open
Referência
CVE-2026-11866
LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
33RISK
open
Referência
CVE-2026-11371
BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
33RISK
open
Referência
CVE-2017-0282
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
CVE-2006-6853remotewindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISK
open
Referência
CVE-2010-5007
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RISK
open
previouspage 368 / 740next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.