Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Google Android Web Browser - '.BMP' File Integer Overflow
CVE-2008-0986dosandroid04 Mar 2008
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier,
23RISK
open
Exploit-DBVexDay Proof
Google Android Web Browser - '.GIF' File Heap Buffer Overflow
CVE-2008-0985dosandroid04 Mar 2008
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows
23RISK
open
Exploit-DBVexDay Proof
TorrentTrader 1.08 - 'msg' HTML Injection
CVE-2008-1173webappsphp03 Mar 2008
Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to i
23RISK
open
Exploit-DBVexDay Proof
KC Wiki 1.0 - '/minimal/wiki.php?page' Remote File Inclusion
CVE-2008-1170webappsphp03 Mar 2008
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
MiniWebsvr 0.0.9a - Remote Directory Traversal
CVE-2007-0919remotewindows03 Mar 2008
Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
KC Wiki 1.0 - '/simplest/wiki.php?page' Remote File Inclusion
CVE-2008-1170webappsphp03 Mar 2008
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
Borland VisiBroker Smart Agent 08.00.00.C1.03 - Multiple Remote Vulnerabilities
CVE-2008-7126doswindows03 Mar 2008
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to
28RISK
open
Exploit-DBVexDay Proof
PHP-Nuke Johannes Hass 'Gaestebuch 2.2 Module - 'id' SQL Injection
CVE-2008-1314webappsphp01 Mar 2008
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Simple PHP Scripts Gallery 0.x - 'index.php' Cross-Site Scripting
CVE-2008-4803webappsphp29 Feb 2008
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Centreon 1.4.2.3 - 'index.php' Local File Inclusion
CVE-2008-1178webappsphp29 Feb 2008
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to re
23RISK
open
Exploit-DBVexDay Proof
NetOffice Dwins 1.3 - Authentication Bypass / Arbitrary File Upload
CVE-2008-2044webappsphp29 Feb 2008
includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of
28RISK
open
Exploit-DBVexDay Proof
PHPMyTourney 2 - '/tourney/index.php' Remote File Inclusion
CVE-2008-1128webappsphp29 Feb 2008
PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
CVE-2008-1180remotehardware28 Feb 2008
Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 b
23RISK
open
Exploit-DBVexDay Proof
Flicks Software AuthentiX 6.3b1 - 'Username' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-1174webappsasp28 Feb 2008
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
CVE-2008-1181webappscgi28 Feb 2008
Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a d
23RISK
open
Exploit-DBVexDay Proof
XRms 1.99.2 - CRM 'msg' Cross-Site Scripting
CVE-2008-1129webappsphp28 Feb 2008
Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow
CVE-2008-0411remotelinux27 Feb 2008
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan - Buffer Overflow (Denial of Service) (PoC)
CVE-2008-1365doswindows27 Feb 2008
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patc
50RISK
open
Exploit-DBVexDay Proof
Nortel UNIStim IP Phone - Remote Ping Denial of Service
CVE-2008-4999doshardware26 Feb 2008
Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping pa
23RISK
open
Exploit-DBVexDay Proof
Galore Simple Shop 3.1 - 'section' SQL Injection
CVE-2008-7033webappsphp25 Feb 2008
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
SurgeFTP 2.3a2 - 'Content-Length' Null Pointer Denial of Service
CVE-2008-1052doswindows25 Feb 2008
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of servi
23RISK
open
Exploit-DBVexDay Proof
Surgemail 3.0 - Real CGI executables Remote Buffer Overflow
CVE-2008-1054doswindows25 Feb 2008
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin Sur
23RISK
open
Exploit-DBVexDay Proof
Softbiz Jokes and Funny Pictures Script - 'sbcat_id' SQL Injection
CVE-2008-1050webappsphp25 Feb 2008
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
MiniNuke 2.1 - 'uid' SQL Injection
CVE-2008-3888webappsasp25 Feb 2008
SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Surgemail and WebMail 3.0 - 'Page' Remote Format String
CVE-2008-1055doswindows25 Feb 2008
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earli
23RISK
open
Exploit-DBVexDay Proof
Packeteer PacketShaper and PolicyCenter 8.2.2 - 'FILELIST' Cross-Site Scripting
CVE-2008-1037remotehardware25 Feb 2008
Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer Packe
23RISK
open
Exploit-DBVexDay Proof
Alkacon OpenCMS 7.0.3 - 'tree_files.jsp' Cross-Site Scripting
CVE-2008-1045webappsjsp25 Feb 2008
Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_fi
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke Recipe Module 1.3 - 'recipeid' SQL Injection
CVE-2008-7226webappsphp23 Feb 2008
SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows
23RISK
open
Exploit-DBVexDay Proof
phpQLAdmin 2.2.7 - Multiple Remote File Inclusions
CVE-2008-0167webappsphp22 Feb 2008
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zer
23RISK
open
Exploit-DBVexDay Proof
XOOPS 'prayerlist' Module - 'cid' SQL Injection
CVE-2008-0936webappsphp21 Feb 2008
SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers t
23RISK
open
previouspage 496 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.