Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
CVE-2008-1898remotewindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISK
open
ReferênciaVexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
CVE-2008-1910doswindows
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
pNews 2.08 - 'shownews' SQL Injection
CVE-2008-2673webappsphp
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RISK
open
ReferênciaVexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RISK
open
ReferênciaVexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
CVE-2008-1915webappsphp
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
CVE-2008-1921webappsphp
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RISK
open
ReferênciaVexDay Proof
Galatolo Web Manager 1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-2699webappsphp
Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and exec
23RISK
open
ReferênciaVexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
CVE-2008-6227webappsphp
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Zune Software - ActiveX Arbitrary File Overwrite
CVE-2008-1933remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to over
28RISK
open
ReferênciaVexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
CVE-2008-1934webappsphp
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
CVE-2008-1936webappsphp
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Web Calendar 4.1 - Blind SQL Injection
CVE-2008-1954webappsphp
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1957webappsphp
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
SFS EZ Webstore - 'where' SQL Injection
CVE-2008-6242webappsphp
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1958webappsphp
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RISK
open
ReferênciaVexDay Proof
Jadu Galaxies - 'categoryId' Blind SQL Injection
CVE-2008-6254webappsphp
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
CVE-2007-2481webappsphp
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh
35RISK
open
ReferênciaVexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
CVE-2007-2483webappsphp
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
CVE-2007-2484webappsphp
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress,
35RISK
open
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
CVE-2008-1961webappsphp
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Aterr 0.9.1 - PHP5 Local File Inclusion
CVE-2008-1962webappsphp
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary loca
23RISK
open
ReferênciaVexDay Proof
Formbankserver 1.9 - 'Name' Directory Traversal
CVE-2007-0055remotewindows
Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read a
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin myflash 1.00 - 'wppath' Remote File Inclusion
CVE-2007-2485webappsphp
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow
35RISK
open
ReferênciaVexDay Proof
PostNuke Module v4bJournal - SQL Injection
CVE-2007-2492webappsphp
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to exec
23RISK
open
ReferênciaVexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
CVE-2008-2898webappsphp
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RISK
open
ReferênciaVexDay Proof
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
CVE-2007-2495doswindows
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
1024 CMS 0.7 - 'download.php' Remote File Disclosure
CVE-2007-2507webappsphp
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to rea
23RISK
open
ReferênciaVexDay Proof
E-topbiz ADManager 4 - 'group' Blind SQL Injection
CVE-2008-6261webappsphp
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Bluo CMS 1.2 - Blind SQL Injection
CVE-2008-6281webappsphp
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
ReferênciaVexDay Proof
z1exchange 1.0 - 'site' SQL Injection
CVE-2008-6284webappsphp
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.