Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PacPoll 4.0 - Database Disclosure
CVE-2008-5981webappsphp
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RISK
open
ReferênciaVexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
CVE-2006-2881webappsphp
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RISK
open
ReferênciaVexDay Proof
Clever Copy 3.0 - 'results.php' SQL Injection
CVE-2008-2909webappsphp
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2911webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arb
23RISK
open
ReferênciaVexDay Proof
PHPMyphorum 1.5a - '/mep/frame.php' Remote File Inclusion
CVE-2007-0361webappsphp
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
CVE-2008-4662webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RISK
open
ReferênciaVexDay Proof
Net-Side.net CMS - 'index.php?cms' Remote File Inclusion
CVE-2007-1707webappsphp
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows rem
23RISK
open
ReferênciaVexDay Proof
CodeAvalanche RateMySite - Database Disclosure
CVE-2008-5896webappsasp
CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows
23RISK
open
ReferênciaVexDay Proof
Free Image Hosting 2.0 - 'AD_BODY_TEMP' Remote File Inclusion
CVE-2007-1715webappsphp
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
EHCP 0.22.8 - Multiple Remote File Inclusions
CVE-2007-6178webappsphp
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier al
23RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - 'Language' Local File Inclusion
CVE-2008-0794webappsphp
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RISK
open
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RISK
open
ReferênciaVexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
CVE-2008-2918webappsphp
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RISK
open
ReferênciaVexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISK
open
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RISK
open
ReferênciaVexDay Proof
Webace-Linkscript 1.3 SE - 'start.php' SQL Injection
CVE-2007-4846webappsphp
SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
CVE-2008-2296webappsphp
PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ourvideo CMS 9.5 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2977webappsphp
Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
tplSoccerSite 1.0 - Multiple SQL Injections
CVE-2008-3251webappsphp
Multiple SQL injection vulnerabilities in tplSoccerSite 1.0 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
YourFreeWorld Shopping Cart - Blind SQL Injection
CVE-2008-4886webappsphp
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5577webappsphp
PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2161webappsphp
Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-inse
23RISK
open
ReferênciaVexDay Proof
Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions
CVE-2008-1409webappsphp
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include a
23RISK
open
ReferênciaVexDay Proof
Boite de News 4.0.1 - 'index.php' Remote File Inclusion
CVE-2006-4123webappsphp
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
CVE-2006-4594webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remo
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.