Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6545webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary we
23RISK
open
ReferênciaVexDay Proof
Belkin Wireless G Router / ADSL2 Modem - Authentication Bypass
CVE-2008-7115remotehardware
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attack
23RISK
open
ReferênciaVexDay Proof
DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
CVE-2008-4502webappsphp
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
CVE-2008-5197webappsphp
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6940webappsphp
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, whi
23RISK
open
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2133webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrar
23RISK
open
ReferênciaVexDay Proof
MailEnable 3.13 SMTP Service - 'VRFY/EXPN' Denial of Service
CVE-2008-1275doswindows
Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x an
23RISK
open
ReferênciaVexDay Proof
WebCalendar 0.9.45 - 'includedir' Remote File Inclusion
CVE-2007-1483webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
CVE-2008-7123webappsphp
Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attack
23RISK
open
ReferênciaVexDay Proof
DeluxeBB 1.2 - Multiple Vulnerabilities
CVE-2008-2194webappsphp
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Jinzora 2.1 - 'media.php' Remote File Inclusion
CVE-2006-7130webappsphp
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
phpDatingClub 3.7 - 'website.php' Local File Inclusion
CVE-2008-3179webappsphp
Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remo
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module PostGuestbook 0.6.1 - 'tpl_pgb_moddir' Remote File Inclusion
CVE-2007-1372webappsphp
PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke all
23RISK
open
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6926webappsphp
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel al
23RISK
open
ReferênciaVexDay Proof
mxBB Module FAQ & RULES 2.0.0 - Remote File Inclusion
CVE-2007-2493webappsphp
PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote at
23RISK
open
ReferênciaVexDay Proof
simple file manager 0.24a - Multiple Vulnerabilities
CVE-2006-6376webappsphp
Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use
23RISK
open
ReferênciaVexDay Proof
e-Vision CMS 2.02 - SQL Injection / Remote Code Execution
CVE-2007-3251webappsphp
Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and
23RISK
open
ReferênciaVexDay Proof
GameCMS Lite 1.0 - 'systemId' SQL Injection
CVE-2008-2225webappsphp
SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
docmint 2.0 - '/engine/require.php' Remote File Inclusion
CVE-2006-5240webappsphp
PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabl
23RISK
open
ReferênciaVexDay Proof
PHPQuickGallery 1.9 - 'textFile' Remote File Inclusion
CVE-2006-6044webappsphp
PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
phpBB Tweaked 3 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0680webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
phpBB Module SupaNav 1.0.0 - 'link_main.php' Remote File Inclusion
CVE-2007-3935webappsphp
PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer - 'MDAC' Remote Code Execution (MS06-014) (Metasploit) (2)
CVE-2006-0003remotewindows
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISK
open
ReferênciaVexDay Proof
Technote 7.2 - Remote File Inclusion
CVE-2009-0441webappsphp
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when registe
23RISK
open
ReferênciaVexDay Proof
wget 1.10.2 - Unchecked Boundary Condition Denial of Service
CVE-2006-6719dosmultiple
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause
23RISK
open
ReferênciaVexDay Proof
IP Reg 0.3 - Multiple SQL Injections
CVE-2007-6579webappsphp
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vl
23RISK
open
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0678webappsphp
images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet
23RISK
open
ReferênciaVexDay Proof
Mozilla Firefox - unclamped loop Denial of Service
CVE-2009-1827dosmultiple
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a
23RISK
open
ReferênciaVexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
CVE-2008-2278webappsphp
SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer - MDAC Remote Code Execution (MS06-014)
CVE-2006-0003remotewindows
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.