Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
Ultra Office - ActiveX Control Arbitrary File Corruption
CVE-2008-3879doswindows
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Contr
23RISK
open
ReferênciaVexDay Proof
ESET SysInspector 1.1.1.0 - 'esiadrv.sys' (PoC)
CVE-2008-4451doswindows
The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users t
23RISK
open
Referência
CVE-2018-6367
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISK
open
ReferênciaVexDay Proof
vxFtpSrv 2.0.3 - 'CWD' Remote Buffer Overflow (PoC)
CVE-2008-4452doswindows
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (c
23RISK
open
Referência
CVE-2026-1631
Feeds for YouTube < 2.6.4 - Subscriber+ License Data Deletion
33RISK
open
Referência
CVE-2018-6367
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RISK
open
ReferênciaVexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
CVE-2008-4455webappsphp
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc
23RISK
open
ReferênciaVexDay Proof
pPIM 1.0 - Upload/Change Password
CVE-2008-4427webappsphp
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RISK
open
ReferênciaVexDay Proof
BBlog 0.7.6 - 'mod' SQL Injection
CVE-2008-4436webappsphp
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2008-4447
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote atta
23RISK
open
Referência
CVE-2018-6368
SQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed acti
23RISK
open
Referência
CVE-2018-6370
SQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under
23RISK
open
ReferênciaVexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
CVE-2008-4449doswindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISK
open
ReferênciaVexDay Proof
mIRC 6.34 - Remote Buffer Overflow
CVE-2008-4449remotewindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISK
open
Referência
CVE-2008-4458
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Dating Zone - 'fage' SQL Injection
CVE-2008-4461webappsphp
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote a
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Visa Zone - 'news_id' SQL Injection
CVE-2008-4462webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Jobs Zone - 'news_id' SQL Injection
CVE-2008-4463webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Mag Zone - 'cat_id' SQL Injection
CVE-2008-4464webappsphp
SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech DVD Zone - 'cat_id' SQL Injection
CVE-2008-4465webappsphp
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
CVE-2008-4467webappsphp
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2026-4524
Authentication Bypass Using an Alternate Path or Channel in GitLab
33RISK
open
Referência
CVE-2026-4527
Cross-Site Request Forgery (CSRF) in GitLab
33RISK
open
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4874remotehardware
The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Reminder Service - SQL Injection
CVE-2008-4881webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2018-6789
CVE-2018-6789CRITICALunder attackransomware
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RISK
open
ReferênciaVexDay Proof
YourFreeWorld Blog Blaster - 'tr.php' SQL Injection
CVE-2008-4883webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Classifieds Hosting - SQL Injection
CVE-2008-4884webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Scrolling Text Ads - SQL Injection
CVE-2008-4885webappsphp
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-4888webappsphp
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbit
23RISK
open
previouspage 458 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.