Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Etomite CMS 0.6.1 - 'rfiles.php' Remote Command Execution
CVE-2006-7070webappsphp
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier all
23RISK
open
ReferênciaVexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
CVE-2007-5453webappsphp
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Web Wiz NewsPad 1.02 - 'sub' Directory Traversal
CVE-2008-0479webappsasp
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitr
23RISK
open
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
CVE-2006-4993webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
CVE-2008-2336webappsphp
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
CVE-2008-2480webappsphp
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
CVE-2007-0585webappsphp
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RISK
open
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1779webappsphp
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2341webappsphp
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
MeltingIce File System 1.0 - Arbitrary Add User
CVE-2008-2348webappsphp
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and e
23RISK
open
ReferênciaVexDay Proof
CMS WebManager-Pro - Multiple SQL Injections
CVE-2008-2351webappsphp
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
How2ASP.net WebBoard 4.1 - SQL Injection
CVE-2008-2417webappsphp
SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Konqueror 3.5.9 - 'color'/'bgcolor' Multiple Remote Crash Vulnerabilities
CVE-2008-5712doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1)
23RISK
open
ReferênciaVexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2446webappsphp
Multiple SQL injection vulnerabilities in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and earlier allow rem
23RISK
open
ReferênciaVexDay Proof
Mambo Module galleria 1.0b - Remote File Inclusion
CVE-2006-3396webappsphp
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows r
23RISK
open
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1780webappsphp
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, wh
23RISK
open
ReferênciaVexDay Proof
PHPRecipeBook 2.35 - 'g_rb_basedir' Remote File Inclusion
CVE-2006-5399webappsphp
PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is e
23RISK
open
ReferênciaVexDay Proof
MyAlbum 3.02 - 'language.inc.php' Remote File Inclusion
CVE-2006-5865webappsphp
PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
MolyX BOARD 2.5.0 - 'index.php?lang' Local File Inclusion
CVE-2007-2778webappsphp
Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - Remote Command Execution
CVE-2009-2111webappsphp
Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-2242doswindows
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RISK
open
ReferênciaVexDay Proof
ItCMS 1.9 - 'boxpop.php' Remote Code Execution
CVE-2008-2192webappsphp
Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inje
23RISK
open
ReferênciaVexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
CVE-2007-2009webappsphp
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
CVE-2008-4380doshardware
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RISK
open
ReferênciaVexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
CVE-2007-2643webappsphp
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP Jokesite 2.0 - 'cat_id' SQL Injection
CVE-2008-2457webappsphp
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5749remotewindows
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Trionic Cite CMS 1.2rev9 - Remote File Inclusion
CVE-2007-5271webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to ex
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.