Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! Component imagebrowser 0.1.5 rc2 - Directory Traversal
CVE-2008-4668webappsphp
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote atta
43RISK
open
ReferênciaVexDay Proof
E-Shop Shopping Cart Script - 'search_results.php' SQL Injection
CVE-2008-5838webappsphp
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script
23RISK
open
ReferênciaVexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
CVE-2008-5840webappsphp
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RISK
open
ReferênciaVexDay Proof
MyPBS - 'seasonID' SQL Injection
CVE-2008-5851webappsphp
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Emefa Guestbook 3.0 - Remote Database Disclosure
CVE-2008-5852webappsasp
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open
ReferênciaVexDay Proof
myPHPscripts Login Session 2.0 - Cross-Site Scripting / Database Disclosure
CVE-2008-5855webappsphp
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
EFS Easy Chat Server 2.2 - Remote Denial of Service
CVE-2004-2466doswindows
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RISK
open
ReferênciaVexDay Proof
WebcamXP 5.3.2.375 - Remote File Disclosure
CVE-2008-5862remotewindows
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra
23RISK
open
ReferênciaVexDay Proof
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
CVE-2008-5859webappsphp
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magi
23RISK
open
ReferênciaVexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
CVE-2009-1210dosmultiple
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RISK
open
ReferênciaVexDay Proof
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
CVE-2008-5864webappsphp
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
CVE-2008-5865webappsphp
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07/2.08 - 'ProxyLogin' Local Stack Overflow
CVE-2008-5868localwindows
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6547webappsphp
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent
23RISK
open
ReferênciaVexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2008-5881webappsphp
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RISK
open
ReferênciaVexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RISK
open
ReferênciaVexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
CVE-2009-1314webappsphp
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RISK
open
ReferênciaVexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5888webappsasp
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RISK
open
ReferênciaVexDay Proof
clickandemail - SQL Injection / Cross-Site Scripting
CVE-2008-5892webappsasp
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1)
23RISK
open
ReferênciaVexDay Proof
Mediatheka 4.2 - 'lang' Local File Inclusion
CVE-2008-5894webappsphp
Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrar
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche Directory - Database Disclosure
CVE-2008-5898webappsasp
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CVE-2008-5899webappsasp
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche Articles - Database Disclosure
CVE-2008-5900webappsasp
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
ReferênciaVexDay Proof
nicLOR CMS - 'sezione_news.php' SQL Injection
CVE-2007-6586webappsphp
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5918webappsphp
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier
23RISK
open
ReferênciaVexDay Proof
Umer Inc Songs Portal Script - 'id' SQL Injection
CVE-2008-5921webappsphp
SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
ASP-DEV Internal E-Mail System - Authentication Bypass
CVE-2008-5926webappsasp
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
FlexPHPNews 0.0.6 / PRO - Authentication Bypass
CVE-2008-5927webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arb
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.