Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Module Arcade 1.0 - 'cid' SQL Injection
CVE-2007-1978webappsphp
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
XOOPS Module PopnupBlog 2.52 - 'postid' Blind SQL Injection
CVE-2007-1979webappsphp
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHP-Fusion Module topliste 1.0 - 'cid' SQL Injection
CVE-2007-1980webappsphp
SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
AROUNDMe 0.7.7 - Multiple Remote File Inclusions
CVE-2007-1986webappsphp
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Weatimages 1.7.1 - ini[langpack] Remote File Inclusion
CVE-2007-1999webappsphp
PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, al
23RISK
open
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2003webappsphp
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check
23RISK
open
ReferênciaVexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
CVE-2019-9831dosandroid
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RISK
open
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.5 - 'calendar.php' Blind SQL Injection
CVE-2007-2211webappsphp
SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
Kodak Image Viewer - TIF/TIFF Code Execution (MS07-055)
CVE-2007-2217localwindows
Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote at
35RISK
open
ReferênciaVexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
CVE-2007-2237doswindows
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RISK
open
ReferênciaVexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
CVE-2007-2244localwindows
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RISK
open
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2304webappsphp
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RISK
open
ReferênciaVexDay Proof
mxBB Module MX Shotcast 1.0 RC2 - 'getinfo1.php' Remote File Inclusion
CVE-2007-2313webappsphp
PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Papoo 3.02 - kontakt menuid SQL Injection
CVE-2007-2320webappsphp
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
JulmaCMS 1.4 - 'file.php' Remote File Disclosure
CVE-2007-2324webappsphp
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
CVE-2007-2458webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arb
28RISK
open
ReferênciaVexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
CVE-2007-2471webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RISK
open
previouspage 188 / 188

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.