Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
HSRS 1.0 - 'addcode.php' Remote File Inclusion
CVE-2006-6154webappsphp
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
CVE-2006-6867webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RISK
open
ReferênciaVexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
CVE-2008-5963webappsphp
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
Firefly 1.1.01 - 'doc_root' Remote File Inclusion
CVE-2007-2456webappsphp
Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_iisfunc.dll' Local Buffer Overflow
CVE-2007-4586doswindows_x86
Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
CVE-2008-1083HIGHlocalwindows
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RISK
open
ReferênciaVexDay Proof
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
CVE-2006-4196webappsphp
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Linksys SPA941 - '\377' Character Remote Denial of Service
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 'Tidy' Extension - Local Buffer Overflow
CVE-2007-3294localwindows
Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow con
23RISK
open
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0' Remote Buffer Overflow
CVE-2007-4903remotewindows
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo
23RISK
open
ReferênciaVexDay Proof
PMECMS 1.0 - config[pathMod] Remote File Inclusion
CVE-2007-2540webappsphp
Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
PHP mSQL (msql_connect) - Local Buffer Overflow (PoC)
CVE-2007-4255dosmultiple
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a lo
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows XP SP2 - 'win32k.sys' Local Privilege Escalation (MS08-025)
CVE-2008-1084localwindows
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP
23RISK
open
ReferênciaVexDay Proof
AFGB Guestbook 2.2 - 'Htmls' Remote File Inclusion
CVE-2006-5307webappsphp
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
muvee autoProducer 6.1 - 'TextOut.dll' ActiveX Remote Buffer Overflow
CVE-2008-2910remotewindows
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll
23RISK
open
ReferênciaVexDay Proof
Cyberfolio 2.0 RC1 - 'av' Remote File Inclusion
CVE-2006-5768webappsphp
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
Social Groupie - 'create_album.php' Arbitrary File Upload
CVE-2008-6367webappsphp
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to
23RISK
open
ReferênciaVexDay Proof
IP3 NetAccess < 4.1.9.6 - Arbitrary File Disclosure
CVE-2007-0883remotehardware
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allo
23RISK
open
ReferênciaVexDay Proof
Samba 3.0.29 (Client) - 'receive_smb_raw()' Buffer Overflow (PoC)
CVE-2008-1105dosmultiple
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote at
35RISK
open
ReferênciaVexDay Proof
Youngzsoft CMailServer 5.4.6 - 'CMailCOM.dll' Remote Overwrite (SEH)
CVE-2008-6922remotewindows
Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary c
23RISK
open
ReferênciaVexDay Proof
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
CVE-2009-0833doswindows
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2009-1315webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri
23RISK
open
ReferênciaVexDay Proof
Adobe Acrobat Reader 8.1.2 - '.PDF' Remote Denial of Service (PoC)
CVE-2008-2549doswindows
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (applicat
35RISK
open
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3448webappsphp
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.3 - User Interface Null Pointer Dereference Crash
CVE-2008-4324doswindows
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3449webappsphp
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the n
23RISK
open
ReferênciaVexDay Proof
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
CVE-2008-1276remotewindows
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JContentSubscription 1.5.8 - Multiple Remote File Inclusions
CVE-2007-5407webappsphp
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! all
35RISK
open
ReferênciaVexDay Proof
Mms Gallery PHP 1.0 - 'id' Remote File Disclosure
CVE-2007-6323webappsphp
Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.