Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
CVE-2006-7107webappsphp
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
MDPro 1.0.76 - 'Cookie PNSVlang' Local File Inclusion
CVE-2006-7112webappsphp
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read an
23RISK
open
ReferênciaVexDay Proof
PHPGiggle 12.08 - 'CFG_PHPGIGGLE_ROOT' File Inclusion
CVE-2006-7119webappsphp
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distribute
23RISK
open
ReferênciaVexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2006-7127webappsphp
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
JAF CMS 4.0 RC1 - 'forum.php' Remote File Inclusion
CVE-2006-7128webappsphp
PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Jinzora 2.6 - '/extras/mt.php' Remote File Inclusion
CVE-2006-7131webappsphp
PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
phpPC 1.04 - Multiple Remote File Inclusions
CVE-2006-7136webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
PHP-Stats 0.1.9.1b - 'PC-REMOTE-ADDR' SQL Injection
CVE-2006-7172webappsphp
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_forum 1.2.4RC3 - Remote File Inclusion
CVE-2006-7208webappsphp
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB co
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (1)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (2)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open
ReferênciaVexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (3)
CVE-2006-7210doswindows
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RISK
open
ReferênciaVexDay Proof
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
CVE-2007-0015remotemultiple
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open
ReferênciaVexDay Proof
AllMyLinks 0.5.0 - 'index.php' Remote File Inclusion
CVE-2007-0171webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
MOTIONBORG Web Real Estate 2.1 - SQL Injection
CVE-2007-0196webappsasp
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
WordPress Core 2.0.6 - 'wp-trackback.php' SQL Injection
CVE-2007-0233webappsphp
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric
28RISK
open
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - AppleTalk 'ATPsndrsp()' Heap Buffer Overflow (PoC)
CVE-2007-0236dososx
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remot
28RISK
open
ReferênciaVexDay Proof
sNews 1.5.30 - Remote Reset Admin Pass / Command Execution
CVE-2007-0261webappsphp
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
CVE-2007-0371doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISK
open
ReferênciaVexDay Proof
DivX Player 6.4.1 - DivXBrowserPlugin 'npdivx32.dll' IE Denial of Service
CVE-2007-0429doswindows
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
CVE-2007-0489webappsphp
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RISK
open
ReferênciaVexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
CVE-2007-0511webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
CVE-2007-0548doswindows
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RISK
open
ReferênciaVexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
CVE-2007-0559webappsphp
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
Xero Portal - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0561webappsphp
Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP co
28RISK
open
ReferênciaVexDay Proof
ASP NEWS 3.0 - 'news_detail.asp' SQL Injection
CVE-2007-0566webappsasp
SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RISK
open
ReferênciaVexDay Proof
Drunken:Golem Portal 0.5.1 Alpha 2 - Remote File Inclusion
CVE-2007-0572webappsphp
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earli
23RISK
open
ReferênciaVexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
CVE-2007-0573webappsphp
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RISK
open
previouspage 130 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.