Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,231cataloged exploits
35,420CVEs with public exploitation
24,695lab-tested
22,233 exploits
ReferênciaVexDay Proof
Frimousse 0.0.2 - 'explorerdir.php' Local Directory Traversal
CVE-2008-0425webappsphp
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary fi
23RISK
open
Referência
CVE-2026-6133
Tenda F451 SafeUrlFilter fromSafeUrlFilter stack-based overflow
41RISK
open
ReferênciaVexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2681webappsphp
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open
ReferênciaVexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open
ReferênciaVexDay Proof
Simple Text-File Login script (SiTeFiLo) 1.0.6 - File Disclosure / Remote File Inclusion
CVE-2008-5762webappsphp
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access
23RISK
open
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open
ReferênciaVexDay Proof
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
CVE-2009-1638webappsasp
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b
23RISK
open
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open
Referência
CVE-2009-4585
UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allo
23RISK
open
Referência
CVE-2009-4585
UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allo
23RISK
open
Referência
CVE-2018-6226
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RISK
open
Referência
CVE-2009-3802
Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") t
23RISK
open
Referência
CVE-2020-12261
Open-AudIT 3.3.0 allows an XSS attack after login.
23RISK
open
ReferênciaVexDay Proof
PHP Webquest 2.6 - Get Database Credentials
CVE-2008-0249webappsphp
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RISK
open
Referência
CVE-2009-3544
Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the ad
23RISK
open
Referência
CVE-2013-5037
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers
23RISK
open
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2863webappsphp
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RISK
open
ReferênciaVexDay Proof
PHP Site Lock 2.0 - 'index.php' SQL Injection
CVE-2008-2865webappsphp
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2009-4760
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which all
23RISK
open
Referência
CVE-2016-4205
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Referência
CVE-2009-4799
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att
23RISK
open
Referência
CVE-2023-31698
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's securit
23RISK
open
Referência
CVE-2016-4206
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
Referência
CVE-2016-4207
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISK
open
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4115webappsphp
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RISK
open
ReferênciaVexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
CVE-2008-5773webappsasp
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
CVE-2008-6269webappsphp
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
CVE-2008-6723webappsphp
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RISK
open
previouspage 403 / 742next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.