Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1555webappsphp
Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to i
23RISK
open
ReferênciaVexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
CVE-2008-6725webappsphp
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHProjekt 5.1 - Multiple Remote File Inclusions
CVE-2006-4204webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
CVE-2008-6726webappsphp
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
Citrix Presentation Server Client - 'WFICA.OCX' ActiveX Heap Buffer Overflow
CVE-2006-6334remotewindows
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.23
35RISK
open
ReferênciaVexDay Proof
PHP 5.2.1 - 'hash_update_file()' Freed Resource Usage
CVE-2007-1581locallinux
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupt
23RISK
open
ReferênciaVexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
CVE-2008-0423webappsphp
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RISK
open
ReferênciaVexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
CVE-2007-1867localwindows
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RISK
open
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RISK
open
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RISK
open
ReferênciaVexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
CVE-2008-6729webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RISK
open
ReferênciaVexDay Proof
Flexphplink Pro - Arbitrary File Upload
CVE-2008-6731webappsphp
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISK
open
ReferênciaVexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
CVE-2008-6738webappsphp
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RISK
open
ReferênciaVexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2008-1609webappsphp
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
CVE-2008-6741webappsphp
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Smart Publisher 1.0.1 - 'filedata' Remote Code Execution
CVE-2008-0503webappsphp
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute ar
28RISK
open
ReferênciaVexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
CVE-2008-6743webappsphp
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RISK
open
ReferênciaVexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISK
open
ReferênciaVexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RISK
open
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RISK
open
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RISK
open
ReferênciaVexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
CVE-2008-6748remotewindows
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RISK
open
ReferênciaVexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
CVE-2007-1060webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RISK
open
ReferênciaVexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
CVE-2007-2425webappsphp
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
CGX 20050314 - 'pathCGX' Remote File Inclusion
CVE-2007-2611webappsphp
Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
ReVou Twitter Clone - Arbitrary File Upload
CVE-2008-6751webappsphp
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows
23RISK
open
ReferênciaVexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
CVE-2008-1613webappsasp
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RISK
open
ReferênciaVexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RISK
open
ReferênciaVexDay Proof
Mambo Component nfnaddressbook 0.4 - Remote File Inclusion
CVE-2007-1596webappsphp
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.