Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
CVE-2008-6347webappsphp
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RISK
open
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-0678webappsphp
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISK
open
ReferênciaVexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
CVE-2006-0821webappsphp
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
CVE-2007-6327doswindows
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RISK
open
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
CVE-2008-2595dosmultiple
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RISK
open
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - SQL Injection
CVE-2008-0683webappsphp
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RISK
open
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RISK
open
ReferênciaVexDay Proof
Social Groupie - 'id' SQL Injection
CVE-2008-6358webappsphp
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
CVE-2006-2849webappsphp
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RISK
open
ReferênciaVexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
CVE-2008-6363doswindows
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RISK
open
ReferênciaVexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
CVE-2006-4920webappsphp
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to exe
28RISK
open
ReferênciaVexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
CVE-2008-0686webappsphp
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RISK
open
ReferênciaVexDay Proof
Ad Management Java - Authentication Bypass
CVE-2008-6365webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
CVE-2008-0692webappsphp
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
CVE-2008-6366webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
CVE-2008-6369webappsphp
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Codefixer MailingListPro - Database Disclosure
CVE-2008-6374webappsasp
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RISK
open
ReferênciaVexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
CVE-2008-6377webappsphp
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
CVE-2008-6378webappsasp
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
CVE-2007-0816doswindows
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RISK
open
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0736webappsasp
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RISK
open
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
ReferênciaVexDay Proof
Rapid Classified 3.1 - Database Disclosure
CVE-2008-6388webappsphp
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RISK
open
ReferênciaVexDay Proof
Visual Events Calendar 1.1 - 'cfg_dir' Remote File Inclusion
CVE-2006-4060webappsphp
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.