Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
CVE-2006-6938webappsphp
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-6941webappsphp
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action
23RISK
open
ReferênciaVexDay Proof
SCart 2.0 - 'page' Remote Code Execution
CVE-2006-7012webappsphp
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RISK
open
ReferênciaVexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-7032webappsphp
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
CVE-2006-7063webappsphp
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
CVE-2006-7080webappsphp
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RISK
open
ReferênciaVexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
CVE-2006-7081webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open
ReferênciaVexDay Proof
PHPWind 5.0.1 - 'AdminUser' Blind SQL Injection
CVE-2006-7101webappsphp
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
CVE-2006-7106webappsphp
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
CVE-2006-7107webappsphp
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
MDPro 1.0.76 - 'Cookie PNSVlang' Local File Inclusion
CVE-2006-7112webappsphp
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read an
23RISK
open
ReferênciaVexDay Proof
TaskTracker 1.5 - 'Customize.asp' Remote Add Administrator
CVE-2007-0049webappsasp
Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add act
23RISK
open
ReferênciaVexDay Proof
AutoDealer 2.0 - 'detail.asp?iPro' SQL Injection
CVE-2007-0053webappsasp
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
IMGallery 2.5 - Create Uploader Script
CVE-2007-0082webappsphp
users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows
23RISK
open
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'language.php' Local File Inclusion
CVE-2007-0098webappsphp
Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allo
23RISK
open
ReferênciaVexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
CVE-2007-0148dososx
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RISK
open
ReferênciaVexDay Proof
AllMyVisitors 0.4.0 - 'index.php' Remote File Inclusion
CVE-2007-0170webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
CVE-2007-0304webappsphp
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
CVE-2007-0314webappsphp
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
CVE-2007-0329webappsphp
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RISK
open
ReferênciaVexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
CVE-2007-0338doswindows
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RISK
open
ReferênciaVexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
CVE-2007-0352localwindows
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RISK
open
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
CVE-2007-0355dososx
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RISK
open
ReferênciaVexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
CVE-2007-0369webappsphp
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
CVE-2007-0631webappsphp
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
CVE-2007-0637webappsphp
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RISK
open
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-0639webappsphp
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RISK
open
ReferênciaVexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
CVE-2007-0643doswindows
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RISK
open
ReferênciaVexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0662webappsphp
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
ExoPHPDesk 1.2.1 - 'faq.php' SQL Injection
CVE-2007-0676webappsphp
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL
23RISK
open
previouspage 185 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.