Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
CVE-2009-1873remotewindows
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RISK
open
ReferênciaVexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
CVE-2009-1915doswindows
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RISK
open
ReferênciaVexDay Proof
DNS Tools (PHP Digger) - Remote Command Execution
CVE-2009-1916webappsphp
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISK
open
ReferênciaVexDay Proof
CPCommerce 1.2.x - 'GLOBALS[prefix]' Arbitrary File Inclusion
CVE-2009-1936CRITICALwebappsphp
_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called direc
60RISK
open
ReferênciaVexDay Proof
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
CVE-2009-1950webappsasp
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1951webappsphp
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RISK
open
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1952webappsphp
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RISK
open
ReferênciaVexDay Proof
Apache mod_dav / svn - Remote Denial of Service
CVE-2009-1955dosmultiple
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RISK
open
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISK
open
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RISK
open
ReferênciaVexDay Proof
Password Protector SD 1.3.1 - Insecure Cookie Handling
CVE-2009-2003webappsphp
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RISK
open
ReferênciaVexDay Proof
Family Connections CMS 1.9 - SQL Injection
CVE-2009-2010webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authen
23RISK
open
ReferênciaVexDay Proof
Worldweaver DX Studio Player < 3.0.29.1 Firefox plugin - Command Injection
CVE-2009-2011remotewindows
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISK
open
ReferênciaVexDay Proof
Frontis 3.9.01.24 - 'source_class' SQL Injection
CVE-2009-2013webappsphp
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Virtue Shopping Mall - 'cid' SQL Injection
CVE-2009-2016webappsphp
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
YNP Portal System 2.2.0 - 'showpage.cgi p' Remote File Disclosure
CVE-2007-4256webappscgi
Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary f
23RISK
open
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.ply' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.spr' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RISK
open
ReferênciaVexDay Proof
Prozilla Pub Site Directory - 'Directory.php?cat' SQL Injection
CVE-2007-4258webappsphp
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
CVE-2007-4279webappsphp
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RISK
open
ReferênciaVexDay Proof
Virtue Book Store - 'cid' SQL Injection
CVE-2009-2017webappsphp
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2019webappsphp
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Virtue Classifieds - 'category' SQL Injection
CVE-2009-2021webappsphp
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
CVE-2009-2096webappsphp
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
CVE-2009-2098webappsphp
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
p4CMS 1.05 - 'abs_pfad' Remote File Inclusion
CVE-2006-4769webappsphp
PHP remote file inclusion vulnerability in abf_js.php in p4CMS 1.05 allows remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
Racer 0.5.3 Beta 5 - Remote Buffer Overflow
CVE-2007-4370remotewindows
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISK
open
ReferênciaVexDay Proof
Getleft 1.2 - Remote Buffer Overflow (PoC)
CVE-2008-6897dosmultiple
Multiple buffer overflows in Getleft.exe in Andres Garcia Getleft 1.2 allow remote attackers to cause a denial of servic
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
CVE-2009-2102webappsphp
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RISK
open
ReferênciaVexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
CVE-2009-2110webappsphp
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.