Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
CVE-2009-0381webappsphp
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RISK
open
ReferênciaVexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
CVE-2009-0384webappsphp
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
AMX Corp. VNC ActiveX Control - 'AmxVnc.dll 1.0.13.0' Remote Buffer Overflow
CVE-2007-3536remotewindows
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers
28RISK
open
ReferênciaVexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2648webappsphp
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
ezusermanager 1.6 - Remote File Inclusion
CVE-2006-2424webappsphp
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RISK
open
ReferênciaVexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISK
open
ReferênciaVexDay Proof
UltraVNC/TightVNC (Multiple VNC Clients) - Multiple Integer Overflows (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISK
open
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISK
open
ReferênciaVexDay Proof
Motorola Wimax modem CPEi300 - File Disclosure / Cross-Site Scripting
CVE-2009-0393remotehardware
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated user
23RISK
open
ReferênciaVexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
CVE-2009-0405webappsphp
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Webring 1.0 - Remote File Inclusion
CVE-2006-4129webappsphp
PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier
23RISK
open
ReferênciaVexDay Proof
Magic Photo Storage Website - '_config[site_path]' File Inclusion
CVE-2007-0181webappsphp
PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote atta
23RISK
open
ReferênciaVexDay Proof
Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion
CVE-2007-0232webappsphp
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Tropicalm Crowell Resource 4.5.2 - 'RESPATH' Remote File Inclusion
CVE-2007-2530webappsphp
Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Media Gallery for Geeklog 1.4.8a - Remote File Inclusion
CVE-2007-2706webappsphp
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows rem
23RISK
open
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
CVE-2009-0409webappsphp
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
CVE-2007-3271webappsphp
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
CVE-2008-0422webappsphp
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RISK
open
ReferênciaVexDay Proof
PowerPoint Viewer OCX 3.2 - ActiveX Control Denial of Service
CVE-2007-2494doswindows
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote
23RISK
open
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - 'clanek' Blind SQL Injection
CVE-2009-0425webappsphp
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Joomla! 1.5 Beta1/Beta2/RC1 - SQL Injection
CVE-2007-4781webappsphp
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote au
23RISK
open
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
CVE-2008-0805webappsphp
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
CVE-2009-0426webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RISK
open
ReferênciaVexDay Proof
VRNews 1.1.1 - 'admin.php' Remote Security Bypass
CVE-2007-3611webappsphp
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attacke
23RISK
open
ReferênciaVexDay Proof
DMXReady Member Directory Manager 1.1 - SQL Injection
CVE-2009-0427webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and ea
23RISK
open
ReferênciaVexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
CVE-2008-1247remotehardware
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.