Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
22,429 exploits
ReferênciaVexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
CVE-2006-2682webappsphp
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6086webappsphp
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
CVE-2006-2818webappsphp
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Joomtracker 1.01 - SQL Injection
CVE-2008-6088webappsphp
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
CVE-2008-6114webappsphp
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
CVE-2006-2888webappsphp
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
CVE-2006-6800webappsphp
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RISK
open
Referência
CVE-2026-10236
SourceCodester Water Billing Management System User Management Endpoint Users.php save improper authorization
33RISK
open
Referência
CVE-2026-23760
CVE-2026-23760CRITICALunder attackransomware
SmarterTools SmarterMail < Build 9511 Authentication Bypass via Password Reset API
100RISK
open
Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RISK
open
ReferênciaVexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
CVE-2008-6197webappsphp
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
MyBB Plugin Custom Pages 1.0 - SQL Injection
CVE-2008-6198webappsphp
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
CVE-2008-6199webappsphp
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RISK
open
Referência
glibc 2.38 - Buffer Overflow
CVE-2023-4911HIGHunder attacklocallinux
Glibc: buffer overflow in ld.so leading to privilege escalation
100RISK
open
ReferênciaVexDay Proof
Cobalt 0.1 - Multiple SQL Injections
CVE-2008-6202webappsasp
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISK
open
Referência
CVE-2024-11954
Pimcore Search Document cross site scripting
33RISK
open
Referência
CVE-2024-12344
TP-Link VN020 F3v(T) FTP USER Command memory corruption
33RISK
open
Referência
CVE-2008-6209
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
CVE-2008-6210webappsphp
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RISK
open
Referência
CVE-2012-1153
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISK
open
ReferênciaVexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
CVE-2008-6227webappsphp
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute ar
23RISK
open
Referência
CVE-2023-23956
A user can supply malicious HTML and JavaScript code that will be executed in the client browser
33RISK
open
Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
Referência
CVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RISK
open
ReferênciaVexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
CVE-2008-6228webappsphp
Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setti
23RISK
open
Referência
CVE-2009-2235
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISK
open
ReferênciaVexDay Proof
Jadu Galaxies - 'categoryId' Blind SQL Injection
CVE-2008-6254webappsphp
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL c
23RISK
open
previouspage 505 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.