Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
ILIAS 3.7.4 - 'ref_id' Blind SQL Injection
CVE-2008-5816webappsphp
SQL injection vulnerability in repository.php in ILIAS 3.7.4 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Simplog 0.9.3.1 - 'comments.php' SQL Injection
CVE-2006-5398webappsphp
SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
jPORTAL 2 - 'mailer.php' SQL Injection
CVE-2007-5974webappsphp
SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Command Execution
CVE-2008-4049remotewindows
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot
23RISK
open
ReferênciaVexDay Proof
FlexBB 0.5.5 - '/inc/start.php?_COOKIE' SQL Bypass
CVE-2006-1978webappsphp
SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
iG Calendar 1.0 - 'user.php?id' SQL Injection
CVE-2007-0130webappsphp
SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Okul Web Otomasyon Sistemi 4.0.1 - SQL Injection
CVE-2007-0305webappsasp
SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
CVE-2007-1719localbsd
Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to
23RISK
open
ReferênciaVexDay Proof
wolioCMS - Authentication Bypass / SQL Injection
CVE-2007-4156webappsphp
Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'LIBC TZ' Enviroment Variable Privilege Escalation
CVE-2006-5556localhp-ux
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other ve
23RISK
open
ReferênciaVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1283webappsphp
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows rem
23RISK
open
ReferênciaVexDay Proof
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
CVE-2009-2153webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject a
23RISK
open
ReferênciaVexDay Proof
Mambo Component Pearl 1.6 - Multiple Remote File Inclusions
CVE-2006-3340webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is ena
28RISK
open
ReferênciaVexDay Proof
ASP EDGE 1.2b - 'user.asp' SQL Injection
CVE-2007-0560webappsasp
SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WSN Guest 1.21 - 'id' SQL Injection
CVE-2007-1517webappsphp
SQL injection vulnerability in comments.php in WSN Guest 1.02 and 1.21 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
TaskDriver 1.2 - Authentication Bypass / SQL Injection
CVE-2007-2622webappsphp
Multiple SQL injection vulnerabilities in TaskDriver 1.2 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3293webappsphp
SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
AdaptCMS Lite 1.3 - Blind SQL Injection
CVE-2008-4524webappsphp
SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3
23RISK
open
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2178webappsphp
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary
23RISK
open
ReferênciaVexDay Proof
DZCP (deV!L_z Clanportal) 1.34 - 'id' SQL Injection
CVE-2006-3347webappsphp
SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
OpenLD 1.2.2 - 'index.php?id' SQL Injection
CVE-2007-3682webappsphp
SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 - SFX Path Stack Overflow
CVE-2006-3912doswindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open
ReferênciaVexDay Proof
phsBlog 0.2 - Bypass SQL Injection Filtering
CVE-2008-4072webappsphp
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - 'Client-IP' SQL Injection
CVE-2007-0971webappsphp
Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
HC Newssystem 1.0-1.4 - 'index.php?ID' SQL Injection
CVE-2007-1417webappsphp
SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
FlashGameScript 1.7 - 'user' SQL Injection
CVE-2007-3646webappsphp
SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ACG News 1.0 - 'aid'/'catid' SQL Injection
CVE-2007-4603webappsphp
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
CVE-2020-23934webappsphp
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RISK
open
ReferênciaVexDay Proof
MyioSoft EasyBookMarker 4.0 - Authentication Bypass
CVE-2008-5652webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
DataLife Engine 4.1 - SQL Injection
CVE-2006-3221webappsphp
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.