Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Barracuda Web Application Firewall - Authentication Bypass
CVE-2014-2595remotehardware
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm
28RISK
open
ReferênciaVexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
CVE-2007-3539webappsphp
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
CVE-2007-4254remotewindows
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RISK
open
ReferênciaVexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
CVE-2008-2267webappsphp
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RISK
open
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6956webappsphp
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RISK
open
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
CVE-2008-0661remotewindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
CVE-2009-0592webappsphp
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RISK
open
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0596webappsphp
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
CVE-2009-0597webappsphp
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RISK
open
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RISK
open
ReferênciaVexDay Proof
PHPMesFilms 1.0 - 'index.php?id' SQL Injection
CVE-2009-0598webappsphp
SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
CVE-2007-6129webappsphp
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RISK
open
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISK
open
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISK
open
ReferênciaVexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISK
open
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISK
open
ReferênciaVexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
CVE-2007-3901remotewindows
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISK
open
ReferênciaVexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
CVE-2007-3932webappsphp
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISK
open
ReferênciaVexDay Proof
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
CVE-2008-5383doswindows
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a deni
23RISK
open
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0672webappsphp
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Morovia Barcode ActiveX Professional 3.3.1304 - Arbitrary File Overwrite
CVE-2007-2644remotewindows
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrar
23RISK
open
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3937webappsasp
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
eCentrex VOIP Client module - 'uacomx.ocx 2.0.1' Remote Buffer Overflow
CVE-2007-4489remotewindows
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote
23RISK
open
ReferênciaVexDay Proof
dotCMS 1.6 - 'id' Local File Inclusion
CVE-2008-3708webappsphp
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
Advanced Electron Forum 1.0.6 - Remote Code Execution
CVE-2008-5090webappsphp
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code em
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.