Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
CVE-2006-5220webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
23RISK
open
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow (PoC)
CVE-2007-0976doswindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
CVE-2009-1828dosmultiple
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RISK
open
ReferênciaVexDay Proof
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
CVE-2007-1837webappsphp
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
CVE-2007-2946doswindows
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RISK
open
ReferênciaVexDay Proof
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
CVE-2007-3487remotewindows
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RISK
open
ReferênciaVexDay Proof
Mambo Component eWriting 1.2.1 - 'cat' SQL Injection
CVE-2008-1297webappsphp
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
SCO UnixWare Merge - 'mcd' Local Privilege Escalation
CVE-2008-6559localsco
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument
23RISK
open
ReferênciaVexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (1)
CVE-2007-0886doslinux
Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (applic
23RISK
open
ReferênciaVexDay Proof
PhpAddEdit 1.3 - 'cookie' Authentication Bypass
CVE-2008-6581webappsphp
login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open
ReferênciaVexDay Proof
IrfanView 4.10 - '.fpx' Memory Corruption
CVE-2008-0493localwindows
fpx.dll 3.9.8.0 in the FlashPix plugin for IrfanView 4.10 allows remote attackers to execute arbitrary code via a crafte
23RISK
open
ReferênciaVexDay Proof
Chilkat XML - ActiveX Arbitrary File Creation/Execution
CVE-2008-4343remotewindows
The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to cr
23RISK
open
ReferênciaVexDay Proof
Miniweb 2.0 - Authentication Bypass
CVE-2008-6582webappsphp
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
Versant Object Database 7.0.1.3 - Commands Execution
CVE-2008-1319remotewindows
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 an
23RISK
open
ReferênciaVexDay Proof
phpBB XS 0.58 - 'functions.php' Remote File Inclusion
CVE-2006-4780webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
LightNEasy sqlite / no database 1.2.2 - Multiple Vulnerabilities
CVE-2008-6592webappsphp
thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remo
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Admin Password Change
CVE-2007-2776webappsphp
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrativ
23RISK
open
ReferênciaVexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2665webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RISK
open
ReferênciaVexDay Proof
PicoFlat CMS 0.5.9 (Windows) - Local File Inclusion
CVE-2008-6604webappsphp
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi
23RISK
open
ReferênciaVexDay Proof
2WIRE DSL Router - 'xslt' Denial of Service
CVE-2008-6605doshardware
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17
23RISK
open
ReferênciaVexDay Proof
Alcatel OmniPCX Office 210/061.1 - Remote Command Execution
CVE-2008-1331webappscgi
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi CMS 4.3.0 < 4.2.3 - 'categ' SQL Injection
CVE-2008-1336webappsphp
SQL injection vulnerability in Koobi CMS 4.2.3 through 4.3.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
MatPo Link 1.2b - Blind SQL Injection / Cross-Site Scripting
CVE-2008-6606webappsphp
SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Groupit 2.00b5 - 'c_basepath' Remote File Inclusion
CVE-2007-1472webappsphp
Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct
23RISK
open
ReferênciaVexDay Proof
MatPo Link 1.2b - SQL Injection
CVE-2008-6606webappsphp
SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
McAfee E-Business Server 8.5.2 - Remote Code Execution / Denial of Service (PoC)
CVE-2008-0127dosmultiple
The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1655webappsphp
Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenti
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2008-5715doswindows
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RISK
open
ReferênciaVexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6612webappsphp
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arb
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.