Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Rankem - File Disclosure / Cross-Site Scripting / Cookie
CVE-2009-0249webappsphp
Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remot
23RISK
open
ReferênciaVexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
CVE-2009-0262doswindows
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Winamp 5.541 - '.mp3'/'.aiff' File Multiple Denial of Service Vulnerabilities
CVE-2009-0263doswindows
Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly e
28RISK
open
ReferênciaVexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
CVE-2007-5824doslinux
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
EntertainmentScript 1.4.0 - 'play.php' SQL Injection
CVE-2008-2393webappsphp
SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Multi-Threaded TFTP 1.1 - GET Denial of Service
CVE-2006-4781doswindows
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
The Walking Club - Authentication Bypass
CVE-2009-0281webappsasp
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
TotalCalendar 2.30 - 'inc' Remote File Inclusion
CVE-2006-7055webappsphp
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
TLS - Renegotiation
CVE-2009-3555CRITICALremotemultiple
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RISK
open
ReferênciaVexDay Proof
OpenGoo 1.1 - Local File Inclusion
CVE-2009-0286webappsphp
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
CVE-2007-4010localwindows
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RISK
open
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RISK
open
ReferênciaVexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
CVE-2009-0301remotewindows
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RISK
open
ReferênciaVexDay Proof
SunOS Release 5.11 snv_101b - Remote IPv6 Crash
CVE-2009-0304dossolaris
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
BibCiter 1.4 - Multiple SQL Injections
CVE-2009-0324webappsphp
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Hospital Management System 4.0 - Persistent Cross-Site Scripting
CVE-2020-5191webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
38RISK
open
ReferênciaVexDay Proof
HP Digital Imaging 'hpqvwocx.dll 2.1.0.556' - 'SaveToFile()' File Write
CVE-2007-3649remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Dig
23RISK
open
ReferênciaVexDay Proof
CMS MAXSITE 1.10 - 'category' SQL Injection
CVE-2008-2487webappsphp
SQL injection vulnerability in index.php in MAXSITE 1.10 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
MetaForum 0.513 Beta - Arbitrary File Upload
CVE-2007-1552webappsphp
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type
23RISK
open
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-0623doswindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISK
open
ReferênciaVexDay Proof
Free Bible Search PHP Script - SQL Injection
CVE-2009-0327webappsphp
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
CVE-2007-3683webappsphp
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
CVE-2008-5705remotelinux
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RISK
open
ReferênciaVexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
CVE-2007-5914webappsphp
Direct static code injection vulnerability in dirsys/modules/config/post.php in JBC Explorer 7.20 RC1 and earlier allows
23RISK
open
ReferênciaVexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
CVE-2009-0331webappsphp
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RISK
open
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0334webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.