Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Referência
CVE-2023-37269
Winter CMS vulnerable to stored XSS through privileged upload of SVG file
28RISK
open
Referência
fuel CMS 1.4.1 - Remote Code Execution (1)
CVE-2018-16763webappslinux
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RISK
open
Referência
CVE-2007-6587
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
CVE-2007-6605doswindows
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6622webappsphp
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
IPTBB 0.5.4 - 'id' SQL Injection
CVE-2007-6639webappsphp
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
SanyBee Gallery 0.1.1 - 'p' Local File Inclusion
CVE-2007-6648webappsphp
Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
matpo bilder galerie 1.1 - Remote File Inclusion
CVE-2007-6649webappsphp
PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Bitweaver R2 CMS - Arbitrary File Upload / Disclosure
CVE-2007-6650webappsphp
Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbit
23RISK
open
ReferênciaVexDay Proof
XCMS 1.83 - Remote Command Execution
CVE-2007-6652webappsphp
cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Host 2.0.7 - 'download.php' Remote File Disclosure
CVE-2007-6653webappsphp
Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary
23RISK
open
ReferênciaVexDay Proof
Mihalism Multi Forum Host 3.0.x - Remote File Inclusion
CVE-2007-6657webappsphp
PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier
23RISK
open
ReferênciaVexDay Proof
oneSCHOOL - 'admin/login.asp' SQL Injection
CVE-2007-6665webappsasp
SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
ZenPhoto 1.1.3 - 'rss.php?albumnr' SQL Injection
CVE-2007-6666webappsphp
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 (Final) - Multiple SQL Injections
CVE-2007-6667webappsphp
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
CVE-2008-0010locallinux
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certai
23RISK
open
ReferênciaVexDay Proof
DivX Player 6.6.0 - ActiveX 'SetPassword()' Denial of Service (PoC)
CVE-2008-0090doswindows
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Int
28RISK
open
ReferênciaVexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
CVE-2008-0099webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Site@School 2.4.10 - Blind SQL Injection
CVE-2008-0129webappsphp
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Tribisur 2.0 - SQL Injection
CVE-2008-0133webappsphp
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
LoudBlog 0.6.1 - 'parsedpage' Remote Code Execution
CVE-2008-0139webappsphp
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to exec
28RISK
open
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0142webappsphp
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
SmallNuke 2.0.4 - Pass Recovery SQL Injection
CVE-2008-0147webappsphp
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remot
23RISK
open
Referência
CVE-2018-8449
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RISK
open
ReferênciaVexDay Proof
Xforum 1.4 - 'topic' SQL Injection
CVE-2008-0279webappsphp
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
DomPHP 0.81 - Remote Add Administrator
CVE-2008-0282webappsphp
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
CVE-2008-0310localsco
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RISK
open
previouspage 466 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.