Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
CVE-2007-1896webappsphp
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RISK
open
ReferênciaVexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
CVE-2007-1899webappsphp
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
CVE-2007-2180doswindows
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RISK
open
ReferênciaVexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
CVE-2007-2167webappsphp
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RISK
open
ReferênciaVexDay Proof
Mozzers SubSystem final - 'subs.php' Remote Code Execution
CVE-2007-2169webappsphp
Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into
23RISK
open
ReferênciaVexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
CVE-2007-2181webappsphp
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
CVE-2007-2183webappsphp
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 / Ademco co. ltd. ATNBaseLoader100 Module - Remote Buffer Overflow
CVE-2007-2938remotewindows
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6,
35RISK
open
ReferênciaVexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
CVE-2007-2940webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
CVE-2007-2941webappsphp
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RISK
open
ReferênciaVexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
CVE-2007-2947webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
CVE-2008-1140localwindows
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
CVE-2008-1141localwindows
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RISK
open
ReferênciaVexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
CVE-2007-2985webappsphp
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RISK
open
ReferênciaVexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
CVE-2008-1160remotehardware
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RISK
open
ReferênciaVexDay Proof
phpComasy 0.8 - 'mod_project_id' SQL Injection
CVE-2008-1164webappsphp
SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
CVE-2008-1177webappsphp
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2369webappsphp
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
CVE-2007-2371webappsphp
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open
ReferênciaVexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
ReferênciaVexDay Proof
EDraw Office Viewer Component - Unsafe Method
CVE-2007-3168remotewindows
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open
ReferênciaVexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
CVE-2007-3524webappsphp
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open
ReferênciaVexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
CVE-2007-3526webappsphp
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
CVE-2007-4005remotewindows
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISK
open
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISK
open
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open
ReferênciaVexDay Proof
Friendly 1.0d1 - 'friendly_path' Remote File Inclusion
CVE-2007-2569webappsphp
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbit
23RISK
open
previouspage 175 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.