Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,137cataloged exploits
35,961CVEs with public exploitation
24,695lab-tested
22,657 exploits
Referência
CVE-2010-1706
Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Phaos 0.9.2 - 'basename()' Remote Command Execution
CVE-2006-4420webappsphp
Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local
23RISK
open
ReferênciaVexDay Proof
PHP Crawler 0.8 - Remote File Inclusion
CVE-2008-4137webappsphp
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RISK
open
ReferênciaVexDay Proof
Fuzzylime CMS 3.03 - 'track.php' Local File Inclusion
CVE-2008-5291webappsphp
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arb
23RISK
open
ReferênciaVexDay Proof
Maran PHP Shop - 'admin.php' Insecure Cookie Handling
CVE-2008-6296webappsphp
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting t
23RISK
open
ReferênciaVexDay Proof
NuralStorm Webmail 0.98b - 'process.php' Remote File Inclusion
CVE-2006-5386webappsphp
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is
23RISK
open
ReferênciaVexDay Proof
OpenForum 0.66 Beta - Remote Reset Admin Password
CVE-2008-7066webappsphp
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct req
23RISK
open
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6381webappsasp
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files vi
23RISK
open
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2134webappsphp
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url param
23RISK
open
ReferênciaVexDay Proof
ASP-Nuke Community 1.5 - Cookie Privilege Escalation
CVE-2006-7152webappsasp
default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo c
23RISK
open
ReferênciaVexDay Proof
McGallery 0.5b - 'download.php' Arbitrary File Download
CVE-2007-1478webappsphp
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil
23RISK
open
ReferênciaVexDay Proof
PBLang 4.67.16.a - Remote Code Execution
CVE-2007-3096webappsphp
Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled,
23RISK
open
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0350webappsphp
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows re
23RISK
open
ReferênciaVexDay Proof
freePHPgallery 0.6 - Cookie Local File Inclusion
CVE-2008-0818webappsphp
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitra
23RISK
open
Referência
CVE-2018-18419
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RISK
open
Referência
CVE-2017-10129
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RISK
open
Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RISK
open
Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Referência
CVE-2010-0674
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
Referência
CVE-2012-6048
Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.
23RISK
open
Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2010-0939
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RISK
open
Referência
CVE-2010-0765
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
Kmita Mail 3.0 - 'file' Remote File Inclusion
CVE-2008-2199webappsphp
PHP remote file inclusion vulnerability in kmitaadmin/kmitam/htmlcode.php in Kmita Mail 3.0 and earlier, when register_g
23RISK
open
Referência
CVE-2004-1580
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2018-11532
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst
23RISK
open
Referência
CVE-2009-2263
Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a
23RISK
open
ReferênciaVexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
CVE-2008-2349webappsphp
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RISK
open
previouspage 636 / 756next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.