Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
FreeCMS.us 0.2 - 'index.php' SQL Injection
CVE-2008-2796webappsphp
SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4644webappsphp
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For H
23RISK
open
ReferênciaVexDay Proof
Yerba SACphp 6.3 - Multiple Vulnerabilities
CVE-2008-5873webappsphp
Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galle
23RISK
open
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0673webappsphp
Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3
23RISK
open
ReferênciaVexDay Proof
Oxygen 2.0 - 'repquote' SQL Injection
CVE-2008-2816webappsphp
SQL injection vulnerability in post.php in Oxygen (aka O2PHP Bulletin Board) 2.0 allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
BASE 1.2.4 - melissa Snort Frontend Remote File Inclusion
CVE-2006-2685webappsphp
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_gl
50RISK
open
ReferênciaVexDay Proof
CCleague Pro 1.0.1RC1 - 'cookie' Remote Code Execution
CVE-2006-4721webappsphp
Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and
23RISK
open
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation
CVE-2008-5708webappsphp
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative us
23RISK
open
ReferênciaVexDay Proof
GL-SH Deaf Forum 6.4.4 - Local File Inclusion
CVE-2007-3535webappsphp
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
RPortal 1.1 - 'file_op' Remote File Inclusion
CVE-2008-6099webappsphp
PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Scribe 0.2 - PHP Remote Code Execution
CVE-2007-5823webappsphp
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or ove
23RISK
open
ReferênciaVexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
CVE-2008-2818webappsphp
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RISK
open
ReferênciaVexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5316webappsphp
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISK
open
ReferênciaVexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open
ReferênciaVexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0473webappsasp
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RISK
open
ReferênciaVexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
CVE-2008-1713doswindows
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RISK
open
ReferênciaVexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
CVE-2008-2834webappsphp
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0453webappsphp
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RISK
open
ReferênciaVexDay Proof
DMXReady Registration Manager 1.1 - Database Disclosure
CVE-2009-1821webappsasp
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, whic
23RISK
open
ReferênciaVexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISK
open
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
CVE-2006-4300webappsasp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2681webappsphp
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISK
open
ReferênciaVexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISK
open
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISK
open
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISK
open
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISK
open
ReferênciaVexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
CVE-2008-2856webappsphp
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
CVE-2006-4891webappsasp
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RISK
open
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5774webappsphp
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.