Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2026-9498
Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine
33RISK
open
ReferênciaVexDay Proof
TubeGuru Video Sharing Script - 'UID' SQL Injection
CVE-2008-3674webappsphp
SQL injection vulnerability in ugroups.php in PozScripts TubeGuru Video Sharing Script allows remote attackers to execut
23RISK
open
Referência
CVE-2018-5981
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
23RISK
open
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISK
open
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
CVE-2008-3704remotewindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISK
open
ReferênciaVexDay Proof
phpArcadeScript 4 - 'cat' SQL Injection
CVE-2008-3711webappsphp
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
cyberBB 0.6 - Multiple SQL Injections
CVE-2008-3718webappsphp
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Ad Board - 'id' SQL Injection
CVE-2008-3725webappsphp
SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
Banner Management Script - 'id' SQL Injection
CVE-2008-3749webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Classifieds - 'category' SQL Injection
CVE-2008-3755webappsphp
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
CVE-2008-3761doswindows
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RISK
open
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RISK
open
Referência
CVE-2008-3765
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
Quick Poll Script - 'id' SQL Injection
CVE-2008-3765webappsphp
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Referência
CVE-2018-5982
SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= requ
23RISK
open
ReferênciaVexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
CVE-2008-3768webappsphp
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RISK
open
ReferênciaVexDay Proof
Pars4U Videosharing 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2008-3772webappsphp
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Matterdaddy Market 1.1 - 'index.php' Multiple SQL Injections
CVE-2008-3783webappsphp
Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow
23RISK
open
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.8.6i - Mms Protocol Handling Heap Overflow (PoC)
CVE-2008-3794dosmultiple
Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i all
28RISK
open
ReferênciaVexDay Proof
Crafty Syntax Live Help 2.14.6 - 'department' SQL Injection
CVE-2008-3845webappsphp
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Acoustica Mixcraft 4.2 - Universal Stack Overflow (SEH)
CVE-2008-3877localwindows
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execut
23RISK
open
ReferênciaVexDay Proof
Ultra Office - ActiveX Control Arbitrary File Corruption
CVE-2008-3879doswindows
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Contr
23RISK
open
Referência
CVE-2026-73033
Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php
41RISK
open
Referência
CVE-2026-19089
Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload
48RISK
open
Referência
CVE-2026-19077
Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization
33RISK
open
ReferênciaVexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RISK
open
Referência
Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection
CVE-2018-6577webappsphp
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta
23RISK
open
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RISK
open
previouspage 477 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.