Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
CVE-2008-3401webappsphp
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3425webappsphp
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RISK
open
ReferênciaVexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
CVE-2008-4204webappsasp
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
CVE-2009-1038webappsphp
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
CVE-2006-4488webappsphp
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RISK
open
ReferênciaVexDay Proof
Stash 1.0.3 - Multiple SQL Injections
CVE-2008-4080webappsphp
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Scriptsez Easy Image Downloader - Local File Download
CVE-2008-6089webappsphp
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitra
23RISK
open
ReferênciaVexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
CVE-2009-1041localfreebsd
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RISK
open
ReferênciaVexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
CVE-2007-6473doswindows
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service
CVE-2009-1045doswindows
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via
23RISK
open
ReferênciaVexDay Proof
WebCalendar 1.0.4 - 'includedir' Remote File Inclusion
CVE-2008-2836webappsphp
PHP remote file inclusion vulnerability in send_reminders.php in WebCalendar 1.0.4 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
BitsCast 0.13.0 - invalid string Remote Denial of Service
CVE-2007-2726doswindows
BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with c
23RISK
open
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1058doswindows
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RISK
open
ReferênciaVexDay Proof
mUnky 0.0.1 - 'zone' Local File Inclusion
CVE-2008-2876webappsphp
Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1059doswindows
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RISK
open
ReferênciaVexDay Proof
eXeScope 6.50 - Local Buffer Overflow
CVE-2009-1063localwindows
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executabl
23RISK
open
ReferênciaVexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
CVE-2008-1862webappsphp
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RISK
open
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-2276webappsphp
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RISK
open
ReferênciaVexDay Proof
Observer 0.3.2.1 - Multiple Remote Command Execution Vulnerabilities
CVE-2008-4318webappsphp
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query
28RISK
open
ReferênciaVexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open
ReferênciaVexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISK
open
ReferênciaVexDay Proof
Icarus 2.0 - '.pgn' Local Stack Overflow (SEH)
CVE-2009-1071localwindows
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or ex
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
CVE-2008-3361remotewindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RISK
open
ReferênciaVexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RISK
open
ReferênciaVexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
CVE-2007-0508webappsphp
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
CVE-2008-4181webappsphp
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RISK
open
ReferênciaVexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
CVE-2007-0983webappsphp
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RISK
open
ReferênciaVexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RISK
open
ReferênciaVexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4378webappsphp
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.