Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

80,409cataloged exploits
37,196CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DBVexDay Proof
AfterLogic MailBee WebMail Pro 3.x - 'default.asp?mode2' Cross-Site Scripting
CVE-2007-5290webappsphp05 Oct 2007
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail
23RISK
open
Exploit-DBVexDay Proof
Pegasus Imaging ImagXpress 8.0 - Arbitrary File Overwrite
CVE-2007-5320remotewindows05 Oct 2007
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - URI Handler Command Execution
CVE-2007-3896remotewindows05 Oct 2007
The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 i
35RISK
open
Exploit-DBVexDay Proof
DropTeam 1.3.3 - Multiple Remote Vulnerabilities
CVE-2007-5264remotemultiple05 Oct 2007
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which all
23RISK
open
Exploit-DBVexDay Proof
AfterLogic MailBee WebMail Pro 3.x - 'login.php?mode' Cross-Site Scripting
CVE-2007-5290webappsphp05 Oct 2007
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail
23RISK
open
Exploit-DBVexDay Proof
Dawn of Time 1.69 MUD Server - Multiple Format String Vulnerabilities
CVE-2007-5265dosmultiple05 Oct 2007
Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Google FeedBurner FeedSmith 2.2 - Cross-Site Request Forgery
CVE-2007-5229webappsphp04 Oct 2007
Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attac
23RISK
open
Exploit-DBVexDay Proof
Cart32 6.x - GetImage Arbitrary File Download
CVE-2007-5253webappscgi04 Oct 2007
c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName par
23RISK
open
Exploit-DBVexDay Proof
Borland Interbase 2007/2007 SP2 - 'open_marker_file' Remote Buffer Overflow (Metasploit)
CVE-2007-5244remotelinux03 Oct 2007
Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versio
50RISK
open
Exploit-DBVexDay Proof
Borland Interbase 2007/2007 SP2 - 'jrd8_create_database' Remote Buffer Overflow (Metasploit)
CVE-2007-5243remotelinux03 Oct 2007
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open
Exploit-DBVexDay Proof
Content Builder 0.7.5 - 'postComment.php' Remote File Inclusion
CVE-2006-3173webappsphp03 Oct 2007
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Uebimiau Webmail 2.7.x - 'index.php' Cross-Site Scripting
CVE-2007-5235webappsphp03 Oct 2007
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Borland Interbase 2007/2007 SP2 - 'INET_connect' Remote Buffer Overflow (Metasploit)
CVE-2007-5243remotelinux03 Oct 2007
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open
Exploit-DBVexDay Proof
DRBGuestbook 1.1.13 - 'index.php' Cross-Site Scripting
CVE-2007-5218webappsphp03 Oct 2007
Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to injec
23RISK
open
Exploit-DBVexDay Proof
Borland Interbase 2007 - 'PWD_db_aliased' Remote Buffer Overflow (Metasploit)
CVE-2007-5243remotelinux03 Oct 2007
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RISK
open
Exploit-DBVexDay Proof
id Software Doom 3 Engine - Console String Visualization Format String
CVE-2007-5248remotemultiple02 Oct 2007
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.
23RISK
open
Exploit-DBVexDay Proof
ASP Product Catalog 1.0 - 'default.asp' SQL Injection
CVE-2008-6875webappsasp01 Oct 2007
SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
Ohesa Emlak Portal 1.0 - 'detay.asp?Emlak' SQL Injection
CVE-2007-5180webappsasp01 Oct 2007
Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Ohesa Emlak Portal 1.0 - 'satilik.asp?Kategori' SQL Injection
CVE-2007-5180webappsasp01 Oct 2007
Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Netkamp Emlak Scripti - Multiple Input Validation Vulnerabilities
CVE-2007-5181webappsasp01 Oct 2007
SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
FSD 2.052/3.000 - 'sysuser.cc sysuser::exechelp' 'HELP' Remote Overflow
CVE-2007-5256remotewindows01 Oct 2007
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote
23RISK
open
Exploit-DBVexDay Proof
FSD 2.052/3.000 - 'servinterface.cc servinterface::sendmulticast' 'PIcallsign' Command Remote Overflow
CVE-2007-5256doswindows01 Oct 2007
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote
23RISK
open
Exploit-DBVexDay Proof
MD-Pro 1.0.76 - 'index.php' Firefox ID SQL Injection
CVE-2007-5222webappsphp29 Sep 2007
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
Tor < 0.1.2.16 - ControlPort Remote Rewrite
CVE-2007-4174remotewindows29 Sep 2007
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allo
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4/2.6 (x86-64) - System Call Emulation Privilege Escalation
CVE-2007-4573locallinux_x86-6427 Sep 2007
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64
23RISK
open
Exploit-DBVexDay Proof
Novus 1.0 - 'Buscar.asp' Cross-Site Scripting
CVE-2007-5142webappsasp27 Sep 2007
Cross-site scripting (XSS) vulnerability in buscar.asp in Solidweb Novus 1.0 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Arbitrary File Upload
CVE-2007-5158remotewindows27 Sep 2007
The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field fo
28RISK
open
Exploit-DBVexDay Proof
JSPWiki 2.5.139 - 'Comment.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5120webappsjsp25 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
SimpGB 1.46.2 - '/admin/emoticonlist.php?l_emoticonlist' Cross-Site Scripting
CVE-2007-5127webappsphp25 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
SimpGB 1.46.2 - '/admin/?l_username' Cross-Site Scripting
CVE-2007-5127webappsphp25 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in SimpGB 1.46.02 allow remote attackers to inject arbitrary web scr
23RISK
open
previouspage 334 / 636next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.