Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
CVE-2006-3980webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RISK
open
ReferênciaVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4532webappsphp
PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and ear
23RISK
open
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISK
open
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RISK
open
ReferênciaVexDay Proof
PG Matchmaking Script - Multiple SQL Injections
CVE-2008-4665webappsphp
SQL injection vulnerability in PG Matchmaking allows remote attackers to execute arbitrary SQL commands via the id param
23RISK
open
ReferênciaVexDay Proof
ArabCMS - 'rss.php' Local File Inclusion
CVE-2008-4667webappsphp
Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitr
23RISK
open
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX Command Execution
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISK
open
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX File Execution(2)
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISK
open
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - Registry Values Creation/Change
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RISK
open
ReferênciaVexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
CVE-2008-4729doswindows
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RISK
open
ReferênciaVexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
CVE-2008-4772webappsphp
SQL injection vulnerability in main/main.php in QuestCMS allows remote attackers to execute arbitrary SQL commands via t
23RISK
open
ReferênciaVexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
CVE-2006-3989webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
BitDefender - Module pdf.xmd Infinite Loop Denial of Service (PoC)
CVE-2008-5409doswindows
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGu
28RISK
open
ReferênciaVexDay Proof
Post Affiliate Pro 3 - 'umprof_status' Blind SQL Injection
CVE-2008-5630webappsphp
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Active Time Billing 3.2 - Authentication Bypass
CVE-2008-5632webappsphp
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Lito Lite CMS - 'cid' SQL Injection
CVE-2008-5636webappsphp
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
CVE-2008-5651webappsphp
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote at
23RISK
open
ReferênciaVexDay Proof
ASP Message Board 2.2.1c - SQL Injection
CVE-2007-5887webappsasp
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
PHP Simple Shop 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4052webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote att
28RISK
open
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
jPORTAL 2 - 'mailer.php' SQL Injection
CVE-2007-5912webappsphp
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
Adobe Shockwave - 'ShockwaveVersion()' Stack Overflow (PoC)
CVE-2007-5941doswindows
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a den
35RISK
open
ReferênciaVexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
CVE-2007-5958dosmultiple
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Tech Article 1.x - SQL Injection
CVE-2008-6050webappsphp
SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
YenerTurk Haber Script 1.0 - SQL Injection
CVE-2006-4064webappsasp
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute
23RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.