Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,057cataloged exploits
36,288CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Solaris 9 (UltraSPARC) - 'sadmind' Remote Code Execution
CVE-2008-4556remotesolaris
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISK
open
ReferênciaVexDay Proof
Opera 9.64 - 7400 nested elements XML Parsing Remote Crash
CVE-2009-1234dosmultiple
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
CVE-2009-1235localosx
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space
23RISK
open
ReferênciaVexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
CVE-2008-4570webappsphp
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
CVE-2006-0099webappsphp
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RISK
open
ReferênciaVexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6112webappsphp
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RISK
open
ReferênciaVexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
CVE-2006-6786webappsphp
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'macfsstat' Local Kernel Memory Leak/Denial of Service
CVE-2009-1237dososx
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'Profil' Kernel Memory Leak/Denial of Service (PoC)
CVE-2009-1237dososx
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RISK
open
ReferênciaVexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
CVE-2007-0638webappsphp
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RISK
open
ReferênciaVexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RISK
open
ReferênciaVexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RISK
open
ReferênciaVexDay Proof
Cartweaver 2.16.11 - 'ProdID' SQL Injection
CVE-2006-2046webappscgi
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RISK
open
ReferênciaVexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
CVE-2009-1256webappsphp
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RISK
open
ReferênciaVexDay Proof
OPENi-CMS 1.0.1beta - 'config' Remote File Inclusion
CVE-2006-4750webappsphp
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, all
23RISK
open
ReferênciaVexDay Proof
KGB 1.9 - 'sesskglogadmin.php' Local File Inclusion
CVE-2007-0337webappsphp
Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and ex
23RISK
open
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2182webappsphp
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Aktueldownload Haber scripti - 'id' SQL Injection
CVE-2007-1015webappsasp
SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module AddressBook 1.2 - Local File Inclusion
CVE-2007-1720webappsphp
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers
23RISK
open
ReferênciaVexDay Proof
public media manager 1.3 - Remote File Inclusion
CVE-2007-5149webappsphp
PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Man
23RISK
open
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-0147webappsphp
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple
28RISK
open
ReferênciaVexDay Proof
ClamAV < 0.94.2 - JPEG Parsing Recursive Stack Overflow (PoC)
CVE-2008-5314dosmultiple
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
CVE-2008-5787webappsphp
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RISK
open
ReferênciaVexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
CVE-2009-1257localwindows
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RISK
open
ReferênciaVexDay Proof
AdaptBB 1.0 - 'topic_id' SQL Injection / Credentials Disclosure
CVE-2009-1259webappsphp
SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
PowerPHPBoard 1.00b - Multiple Local File Inclusions
CVE-2008-1534webappsphp
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitr
23RISK
open
ReferênciaVexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
CVE-2008-3237webappsphp
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
Link Request Contact Form 3.4 - Remote Code Execution
CVE-2007-3199webappsphp
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
CVE-2007-5646webappsphp
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RISK
open
ReferênciaVexDay Proof
easysite 2.3 - Multiple Vulnerabilities
CVE-2008-4155webappsphp
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.