Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3763webappsphp
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is
23RISK
open
ReferênciaVexDay Proof
TlGuestBook 1.2 - Insecure Cookie Handling
CVE-2008-5065webappsphp
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBo
23RISK
open
ReferênciaVexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
CVE-2008-5883webappsphp
Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list a
23RISK
open
ReferênciaVexDay Proof
PhpCommander 3.0 - 'upload' Remote Code Execution
CVE-2006-4636webappsphp
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2872webappsphp
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
WebBuilder 2.0 - 'StageLoader.php' Remote File Inclusion
CVE-2007-0703webappsphp
PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
CVE-2009-0325webappsphp
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RISK
open
ReferênciaVexDay Proof
Webavis 0.1.1 - 'class.php?root' Remote File Inclusion
CVE-2007-2943webappsphp
PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
CVE-2009-0639webappsphp
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
PBEmail 7 - ActiveX Edition Insecure Method
CVE-2007-5446remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows
23RISK
open
ReferênciaVexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
CVE-2008-2892webappsphp
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
PageSquid CMS 0.3 Beta - 'index.php' SQL Injection
CVE-2008-2897webappsphp
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
CVE-2008-5853webappsphp
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i
23RISK
open
ReferênciaVexDay Proof
Absolute FAQ Manager 6.0 - Insecure Cookie Handling
CVE-2008-6854webappsphp
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative acc
23RISK
open
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1489webappsphp
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by set
23RISK
open
ReferênciaVexDay Proof
Teraway LinkTracker 1.0 - Insecure Cookie Handling
CVE-2009-1617webappsphp
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l
23RISK
open
ReferênciaVexDay Proof
Belkin F5D9230-4 Wireless G Plus MIMO Router - Authentication Bypass
CVE-2008-0403remotehardware
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, whic
23RISK
open
ReferênciaVexDay Proof
Gobbl CMS 1.0 - Insecure Cookie Handling
CVE-2008-5880webappsphp
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setti
23RISK
open
ReferênciaVexDay Proof
ASPPortal 3.2.5 - Database Disclosure
CVE-2008-6382webappsasp
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote a
23RISK
open
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
CVE-2006-5597remotewindows
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RISK
open
ReferênciaVexDay Proof
SH-News 3.0 - Insecure Cookie Handling
CVE-2008-6664webappsphp
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RISK
open
ReferênciaVexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
CVE-2007-1932webappsphp
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RISK
open
ReferênciaVexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
CVE-2007-2942webappsphp
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
CVE-2008-6863webappsphp
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RISK
open
ReferênciaVexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
CVE-2007-3403webappsphp
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RISK
open
ReferênciaVexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
CVE-2007-4053webappsphp
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ProManager 0.73 - 'config.php' Local File Inclusion
CVE-2008-2687webappsphp
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute ar
23RISK
open
ReferênciaVexDay Proof
Thyme Calendar 1.3 - SQL Injection
CVE-2007-2621webappsphp
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
jaxultrabb 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2966webappsphp
Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbit
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.