Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,332 exploits
ReferênciaVexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RISK
open
ReferênciaVexDay Proof
Simple DNS Plus 5.0/4.1 - Remote Denial of Service
CVE-2008-3208doswindows
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of servic
23RISK
open
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RISK
open
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RISK
open
Referência
CVE-2026-9822
WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers
33RISK
open
ReferênciaVexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RISK
open
ReferênciaVexDay Proof
WinRemotePC Full+Lite 2008 r.2server - Denial of Service
CVE-2008-3269doswindows
WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of s
28RISK
open
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RISK
open
ReferênciaVexDay Proof
Aprox CMS Engine 5.1.0.4 - 'index.php' SQL Injection
CVE-2008-3291webappsphp
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
EZWebAlbum - Insecure Cookie Handling
CVE-2008-3292webappsphp
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se
23RISK
open
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3302webappsphp
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RISK
open
Referência
CVE-2026-10873
Shibby Tomato Web UI rstats rstats_path os command injection
41RISK
open
Referência
CVE-2026-10872
Shibby Tomato Web UI rc start_vpnserver os command injection
41RISK
open
Referência
CVE-2026-10871
Shibby Tomato Web UI rc start_6rd_tunnel os command injection
41RISK
open
Referência
CVE-2026-50266
In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p
28RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07 - server header Remote Code Execution
CVE-2008-3361remotewindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RISK
open
ReferênciaVexDay Proof
PixelPost 1.7.1 - 'language_full' Local File Inclusion
CVE-2008-3365webappsphp
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows r
23RISK
open
Referência
CVE-2008-3371
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RISK
open
ReferênciaVexDay Proof
TalkBack 2.3.5 - 'Language' Local File Inclusion
CVE-2008-3371webappsphp
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RISK
open
ReferênciaVexDay Proof
Gregarius 0.5.4 - SQL Injection
CVE-2008-3374webappsphp
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
PHPTest 0.6.3 - SQL Injection
CVE-2008-3377webappsphp
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
MojoAuto - Blind SQL Injection
CVE-2008-3383webappscgi
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Video Share Enterprise 4.5.1 - 'UID' SQL Injection
CVE-2008-3386webappsphp
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
PHPFootball 1.6 - SQL Injection
CVE-2008-3387webappsphp
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3400webappsphp
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, whic
23RISK
open
ReferênciaVexDay Proof
MojoPersonals - Blind SQL Injection
CVE-2008-3403webappscgi
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
IceBB 1.0-RC9.2 - Blind SQL Injection / Session Hijacking
CVE-2008-3416webappsphp
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'r' SQL Injection
CVE-2008-3417webappsasp
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitr
23RISK
open
previouspage 454 / 745next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.