Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,039cataloged exploits
36,284CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHPProfiles 4.5.2 Beta - 'body_comm.inc.php' Remote File Inclusion
CVE-2008-1051webappsphp
PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers t
28RISK
open
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RISK
open
ReferênciaVexDay Proof
Destar 0.2.2-5 - Arbitrary Add New User
CVE-2008-6538webappsphp
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin Sniplets 1.1.2 - Remote File Inclusion / Cross-Site Scripting / Remote Code Execution
CVE-2008-1061webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote at
38RISK
open
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC)
CVE-2008-3702doswindows
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used
23RISK
open
ReferênciaVexDay Proof
Apple iTunes 8.0.2.20/QuickTime 7.5.5 - '.mov' Multiple Off By Overflows (PoC)
CVE-2008-5406doswindows
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denia
23RISK
open
ReferênciaVexDay Proof
Destar 0.2.2-5 - Arbitrary Add Admin
CVE-2008-6539webappsphp
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitra
23RISK
open
ReferênciaVexDay Proof
osTicket 1.12 - Formula Injection
CVE-2019-14749webappsphp
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex
23RISK
open
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.3 - 'catid' SQL Injection
CVE-2008-1077webappsphp
SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Jooml
23RISK
open
ReferênciaVexDay Proof
Joomla! 1.5.12 TinyMCE - Remote Code Execution (via Arbitrary File Upload)
CVE-2011-4906webappsphp
Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.
23RISK
open
ReferênciaVexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
CVE-2006-1243webappsphp
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Fundanemt 2.2.0 - 'spellcheck.php' Remote Code Execution
CVE-2007-2935webappsphp
core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via she
23RISK
open
ReferênciaVexDay Proof
FretsWeb 1.2 - Multiple Local File Inclusions
CVE-2009-2109webappsphp
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director
23RISK
open
ReferênciaVexDay Proof
HSRS 1.0 - 'addcode.php' Remote File Inclusion
CVE-2006-6154webappsphp
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
CVE-2006-6867webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RISK
open
ReferênciaVexDay Proof
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
CVE-2006-4196webappsphp
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Linksys SPA941 - '\377' Character Remote Denial of Service
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 'Tidy' Extension - Local Buffer Overflow
CVE-2007-3294localwindows
Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow con
23RISK
open
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0' Remote Buffer Overflow
CVE-2007-4903remotewindows
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo
23RISK
open
ReferênciaVexDay Proof
PMECMS 1.0 - config[pathMod] Remote File Inclusion
CVE-2007-2540webappsphp
Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
PHP mSQL (msql_connect) - Local Buffer Overflow (PoC)
CVE-2007-4255dosmultiple
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a lo
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows XP SP2 - 'win32k.sys' Local Privilege Escalation (MS08-025)
CVE-2008-1084localwindows
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP
23RISK
open
ReferênciaVexDay Proof
Adobe Acrobat Reader 8.1.2 - '.PDF' Remote Denial of Service (PoC)
CVE-2008-2549doswindows
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (applicat
35RISK
open
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3448webappsphp
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.3 - User Interface Null Pointer Dereference Crash
CVE-2008-4324doswindows
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3449webappsphp
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the n
23RISK
open
ReferênciaVexDay Proof
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
CVE-2008-1276remotewindows
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JContentSubscription 1.5.8 - Multiple Remote File Inclusions
CVE-2007-5407webappsphp
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! all
35RISK
open
ReferênciaVexDay Proof
Mms Gallery PHP 1.0 - 'id' Remote File Disclosure
CVE-2007-6323webappsphp
Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.