Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
lustig.cms Beta 2.5 - 'forum.php?view' Remote File Inclusion
CVE-2007-5138webappsphp
PHP remote file inclusion vulnerability in forum/forum.php in lustig.cms BETA 2.5 allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
Litespeed Web Server 3.2.3 - Source Code Disclosure
CVE-2007-5654remotemultiple
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
35RISK
open
ReferênciaVexDay Proof
phpFaber URLInn 2.0.5 - 'dir_ws' Remote File Inclusion
CVE-2007-5754webappsphp
PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
DeluxeBB 1.2 - Multiple Vulnerabilities
CVE-2008-2195webappsphp
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrator
23RISK
open
ReferênciaVexDay Proof
Post Affiliate Pro 2.0 - 'md' Local File Inclusion
CVE-2008-4602webappsphp
Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and p
23RISK
open
ReferênciaVexDay Proof
Joomla! Component iDoBlog b24 - SQL Injection
CVE-2008-2627webappsphp
SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, all
23RISK
open
ReferênciaVexDay Proof
NukeSentinel 2.5.05 - 'nsbypass.php' Blind SQL Injection
CVE-2007-1171webappsphp
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 al
23RISK
open
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'defs.php' Local File Inclusion
CVE-2008-5989webappsphp
Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows
23RISK
open
ReferênciaVexDay Proof
Joomla! Component PU Arcade 2.1.3 - SQL Injection
CVE-2007-6663webappsphp
SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2
23RISK
open
ReferênciaVexDay Proof
PHPmyGallery 1.0beta2 - Local/Remote File Inclusion
CVE-2008-6315webappsphp
PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attack
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Forum Pay Per Post Exchange 2.0 - SQL Injection
CVE-2008-0440webappsphp
AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access
23RISK
open
ReferênciaVexDay Proof
CMSbright - 'id_rub_page' SQL Injection
CVE-2008-6991webappsphp
SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
PHPRunner 4.2 - 'SearchOption' Blind SQL Injection
CVE-2009-0963webappsphp
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow (PoC)
CVE-2008-3360doswindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_Eventing 1.6.x - Blind SQL Injection
CVE-2009-0421webappsphp
SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
CVE-2008-0613webappsphp
Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary we
23RISK
open
ReferênciaVexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
CVE-2009-1323webappsphp
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
2DayBiz Business Community Script - Multiple Vulnerabilities
CVE-2009-1651webappsphp
SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5742webappsphp
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbit
23RISK
open
ReferênciaVexDay Proof
Intel 2200BG 802.11 - disassociation packet Kernel Memory Corruption
CVE-2007-0686doswindows
The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of servi
23RISK
open
ReferênciaVexDay Proof
PHPfan 3.3.4 - 'init.php' Remote File Inclusion
CVE-2008-6251webappsphp
PHP remote file inclusion vulnerability in includes/init.php in phpFan 3.3.4 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6524webappsphp
resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrar
23RISK
open
ReferênciaVexDay Proof
Dagger CMS 2008 - 'dir_inc' Remote File Inclusion
CVE-2008-6635webappsphp
PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when re
23RISK
open
ReferênciaVexDay Proof
wpQuiz 2.7 - Multiple SQL Injections
CVE-2007-6172webappsphp
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id
23RISK
open
ReferênciaVexDay Proof
Joomla! Component gigCalendar 1.0 - SQL Injection
CVE-2009-0726webappsphp
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers
23RISK
open
ReferênciaVexDay Proof
123tkShop 0.9.1 - Remote Authentication Bypass
CVE-2007-6458webappsphp
SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
NetHoteles 3.0 - 'ficha.php' SQL Injection
CVE-2009-1346webappsphp
SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
IntelliTamper 2.07/2.08 Beta 4 - A HREF Remote Buffer Overflow
CVE-2008-3360remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RISK
open
ReferênciaVexDay Proof
webSPELL 4.2.0c - Bypass BBCode Cross-Site Scripting Cookie Stealing
CVE-2009-1408webappsphp
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HT
23RISK
open
ReferênciaVexDay Proof
bwired - 'index.php?newsID' SQL Injection
CVE-2007-3978webappsphp
Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID paramet
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.