Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
xeCMS 1.x - 'view.php' Remote File Disclosure
CVE-2007-6508webappsphp
Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (
23RISK
open
ReferênciaVexDay Proof
TlAds 1.0 - Remote Insecure Cookie Handling
CVE-2008-4783webappsphp
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo
23RISK
open
ReferênciaVexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0828webappsphp
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
CVE-2006-0308webappsphp
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RISK
open
ReferênciaVexDay Proof
PortailPHP mod_phpalbum 2.1.5 - 'chemin' Remote File Inclusion
CVE-2006-4498webappsphp
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remo
23RISK
open
ReferênciaVexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
CVE-2009-1050webappsphp
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYou
23RISK
open
ReferênciaVexDay Proof
sBLOG 0.7.3 Beta - '/inc/lang.php' Local File Inclusion
CVE-2007-1801webappsphp
Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arb
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Jobs 2.4 - 'cid' SQL Injection
CVE-2007-2370webappsphp
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
CVE-2007-3633remotewindows
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 al
23RISK
open
ReferênciaVexDay Proof
DevMass Shopping Cart 1.0 - Remote File Inclusion
CVE-2007-6133webappsphp
PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remo
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer - XML Parsing Remote Buffer Overflow
CVE-2008-4844remotewindows
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISK
open
ReferênciaVexDay Proof
LeadTools Raster Thumbnail Object Library - 'LTRTM14e.dll' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7089webappsphp
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script
23RISK
open
ReferênciaVexDay Proof
SiteDepth CMS 3.44 - 'ShowImage.php?name' File Disclosure
CVE-2007-3404webappsphp
Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin WassUp 1.4.3 - 'to_date' SQL Injection
CVE-2008-0520webappsphp
Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote att
23RISK
open
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1663webappsphp
Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4875remotehardware
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and
23RISK
open
ReferênciaVexDay Proof
chCounter 3.1.3 - Authentication Bypass
CVE-2009-1347webappsphp
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Apollo 37zz - '.m3u' Local Heap Overflow (PoC)
CVE-2009-1351doswindows
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and p
23RISK
open
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1368webappsphp
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1369webappsphp
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) p
23RISK
open
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4876remotehardware
Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firm
23RISK
open
ReferênciaVexDay Proof
WebCards 1.3 - SQL Injection
CVE-2008-4877webappsphp
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Maran PHP Shop - 'prod.php' SQL Injection
CVE-2008-4879webappsphp
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Xilisoft Video Converter Wizard 3 - '.cue' Stack Buffer Overflow (PoC)
CVE-2009-1370doswindows
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote att
23RISK
open
ReferênciaVexDay Proof
OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
CVE-2009-1386dosmultiple
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RISK
open
ReferênciaVexDay Proof
CRE Loaded 6.2 - 'products_id' SQL Injection
CVE-2009-1403webappsphp
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Flatchat 3.0 - 'pmscript.php' Local File Inclusion
CVE-2009-1486webappsphp
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitra
23RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1488webappsphp
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbit
23RISK
open
ReferênciaVexDay Proof
Invision Power Board 2.0.3 - 'login.php' SQL Injection
CVE-2005-1598webappsphp
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.