Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,772cataloged exploits
35,760CVEs with public exploitation
24,695lab-tested
22,492 exploits
ReferênciaVexDay Proof
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
CVE-2008-4250CRITICALunder attackremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISK
open
ReferênciaVexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
CVE-2008-4331webappsphp
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
PHP infoBoard 7 - Plus Insecure Cookie Handling
CVE-2008-4334webappsphp
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in
23RISK
open
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4346webappsphp
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary
23RISK
open
ReferênciaVexDay Proof
pNews 2.03 - 'newsid' SQL Injection
CVE-2008-4347webappsphp
SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4352webappsphp
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary
23RISK
open
Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open
ReferênciaVexDay Proof
iBoutique 4.0 - 'cat' SQL Injection
CVE-2008-4354webappsphp
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbi
23RISK
open
Referência
CVE-2018-6365
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RISK
open
ReferênciaVexDay Proof
pForum 1.30 - 'showprofil.php' SQL Injection
CVE-2008-4355webappsphp
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.7 - 'probe read' Local Kernel Denial of Service (PoC)
CVE-2008-4363doswindows
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RISK
open
ReferênciaVexDay Proof
ParsaWeb CMS - 'Search' SQL Injection
CVE-2008-4364webappsasp
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
AvailScript Photo Album - 'pics.php' Multiple Vulnerabilities
CVE-2008-4370webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
AvailScript Jobs Portal Script - 'jid' SQL Injection
CVE-2008-4373webappsphp
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
AvailScript Classmate Script - 'viewprofile.php' SQL Injection
CVE-2008-4375webappsphp
SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Live TV Script - 'index.php?mid' SQL Injection
CVE-2008-4376webappsphp
SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2026-44195
OPNsense: Authentication lockout bypass
33RISK
open
ReferênciaVexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
CVE-2008-4470localwindows
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RISK
open
ReferênciaVexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
CVE-2008-4486webappsphp
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RISK
open
ReferênciaVexDay Proof
Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection
CVE-2008-4497webappsphp
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
IP Reg 0.4 - Blind SQL Injection
CVE-2008-4523webappsphp
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RISK
open
Referência
CVE-2008-4525
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Mod recept - 'kat_id' SQL Injection
CVE-2008-4527webappsphp
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RISK
open
ReferênciaVexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RISK
open
ReferênciaVexDay Proof
Macrovision FlexNet DownloadManager - Insecure Methods
CVE-2008-4587remotewindows
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.
28RISK
open
previouspage 539 / 750next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.