Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Natterchat 1.12 - Database Disclosure
CVE-2008-5602webappsasp
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote at
23RISK
open
ReferênciaVexDay Proof
ASP Message Board 2.2.1c - SQL Injection
CVE-2007-5887webappsasp
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
PHP Simple Shop 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4052webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote att
28RISK
open
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
jPORTAL 2 - 'mailer.php' SQL Injection
CVE-2007-5912webappsphp
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Adobe Shockwave - 'ShockwaveVersion()' Stack Overflow (PoC)
CVE-2007-5941doswindows
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a den
35RISK
open
ReferênciaVexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
CVE-2007-5958dosmultiple
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RISK
open
ReferênciaVexDay Proof
SAPID Shop 1.2 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4062webappsphp
PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier a
23RISK
open
ReferênciaVexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5955webappsphp
SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5980webappsphp
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allow
23RISK
open
ReferênciaVexDay Proof
barcodegen 2.0.0 - Local File Inclusion
CVE-2008-5993webappsphp
Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote atta
23RISK
open
ReferênciaVexDay Proof
IncCMS Core 1.0.0 - 'settings.php' Remote File Inclusion
CVE-2006-5304webappsphp
PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
SAPID Blog Beta 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4063webappsphp
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
WebBiscuits Modules Controller 1.1 - Remote File Inclusion / Remote File Disclosure
CVE-2008-6138webappsphp
PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JD-Wiki 1.0.2 - Remote File Inclusion
CVE-2006-4074webappsphp
PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and ear
23RISK
open
ReferênciaVexDay Proof
SuperNET Shop 1.0 - SQL Injection
CVE-2008-6204webappsasp
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
SQLiteWebAdmin 0.1 - 'tpl.inc.php' Remote File Inclusion
CVE-2006-4102webappsphp
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allo
23RISK
open
ReferênciaVexDay Proof
phNNTP 1.3 - 'article-raw.php' Remote File Inclusion
CVE-2006-4103webappsphp
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
JaxUltraBB 2.0 - 'delete.php' Remote Auto Deface
CVE-2006-5511webappsphp
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, all
23RISK
open
ReferênciaVexDay Proof
SFS EZ BIZ PRO - SQL Injection
CVE-2008-6245webappsphp
SQL injection vulnerability in track.php in Scripts For Sites (SFS) EZ BIZ PRO allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
SFS EZ Webring - 'cat' SQL Injection
CVE-2008-6246webappsphp
SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
PHPMyRing 4.2.0 - 'view_com.php' SQL Injection
CVE-2006-4114webappsphp
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Sciurus Hosting Panel - Remote Code Injection
CVE-2007-6082webappsphp
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RISK
open
ReferênciaVexDay Proof
Apple Safari / QuickTime 7.3 - RTSP Content-Type Remote Buffer Overflow
CVE-2007-6166remoteosx
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.1.4 - SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISK
open
ReferênciaVexDay Proof
VWar 1.50 R14 - 'online.php' SQL Injection
CVE-2006-4142webappsphp
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
KB-Bestellsystem - 'kb_whois.cgi' Command Execution
CVE-2007-6176webappscgi
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell
23RISK
open
ReferênciaVexDay Proof
TuMusika Evolution 1.7R5 - Remote File Disclosure
CVE-2007-6188webappsphp
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
Chaussette 080706 - '_BASE' Remote File Inclusion
CVE-2006-4159webappsphp
Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute ar
28RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.