Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
CVE-2007-3526webappsphp
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
CVE-2007-4005remotewindows
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISK
open
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISK
open
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open
ReferênciaVexDay Proof
Friendly 1.0d1 - 'friendly_path' Remote File Inclusion
CVE-2007-2569webappsphp
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Wikivi5 - 'show.php?sous_rep' Remote File Inclusion
CVE-2007-2570webappsphp
PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
XOOPS Module wfquotes 1.0 - SQL Injection
CVE-2007-2571webappsphp
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
NoAh 0.9 pre 1.2 - 'mfa_theme.php' Remote File Inclusion
CVE-2007-2572webappsphp
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect,
23RISK
open
ReferênciaVexDay Proof
Notepad++ 4.1 (Windows x86) - '.ruby' File Processing Buffer Overflow
CVE-2007-2666localwindows_x86
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, all
28RISK
open
ReferênciaVexDay Proof
webdesproxy 0.0.1 - GET Remote Buffer Overflow
CVE-2007-2668remotewindows
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involvin
23RISK
open
ReferênciaVexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open
ReferênciaVexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2901webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitra
23RISK
open
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RISK
open
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3139webappsphp
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
CVE-2007-3958doswindows
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RISK
open
ReferênciaVexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
CVE-2007-3997localmultiple
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RISK
open
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Remote Delete File
CVE-2007-4031remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
23RISK
open
ReferênciaVexDay Proof
AuraCMS Forum Module - SQL Injection
CVE-2007-4171webappsphp
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RISK
open
ReferênciaVexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
CVE-2007-4377remotewindows
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
CVE-2007-4606webappsphp
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RISK
open
ReferênciaVexDay Proof
Postcast Server Pro 3.0.61 / Quiksoft EasyMail - 'emsmtp.dll 6.0.1' Remote Buffer Overflow
CVE-2007-4607remotewindows
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RISK
open
ReferênciaVexDay Proof
MWOpen E-Commerce - 'leggi_commenti.asp' SQL Injection
CVE-2007-6292webappsasp
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
CVE-2007-4712webappsphp
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RISK
open
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player - Remote Overflow (SEH)
CVE-2007-4722remotewindows
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RISK
open
ReferênciaVexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
CVE-2007-4734localwindows
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RISK
open
previouspage 176 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.