Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISK
open
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - PHP_binary Session Deserialization Information Leak
CVE-2007-1380localmultiple
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-
23RISK
open
ReferênciaVexDay Proof
WEBO (Web ORGanizer) 1.0 - 'baseDir' Remote File Inclusion
CVE-2007-1391webappsphp
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows r
23RISK
open
ReferênciaVexDay Proof
Snort 2.6.1.1/2.6.1.2/2.7.0 - 'fragementation' Remote Denial of Service
CVE-2007-1398dosmultiple
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip
23RISK
open
ReferênciaVexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - 'UDP' Denial of Service
CVE-2007-1404doswindows
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP p
35RISK
open
ReferênciaVexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
CVE-2007-1412localmultiple
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RISK
open
ReferênciaVexDay Proof
PHP 4.4.6 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RISK
open
ReferênciaVexDay Proof
SonicMailer Pro 3.2.3 - 'index.php' SQL Injection
CVE-2007-1425webappsphp
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute
23RISK
open
Referência
CVE-2017-0146
CVE-2017-0146HIGHunder attackransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Referência
CVE-2017-0285
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RISK
open
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Referência
CVE-2021-46417
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege
50RISK
open
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RISK
open
ReferênciaVexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
CVE-2007-1578doswindows_x86
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RISK
open
Referência
CVE-2017-17572
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RISK
open
ReferênciaVexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
CVE-2007-1579remotewindows
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RISK
open
Referência
CVE-2017-17572
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISK
open
ReferênciaVexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
CVE-2007-1613webappsphp
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Lyrics 2.0 - 'index.php?recid' SQL Injection
CVE-2007-1616webappsphp
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitr
23RISK
open
Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1617webappsphp
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RISK
open
Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RISK
open
ReferênciaVexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
CVE-2007-1620webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RISK
open
ReferênciaVexDay Proof
Active Photo Gallery - 'catid' SQL Injection
CVE-2007-1629webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RISK
open
Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISK
open
ReferênciaVexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
CVE-2007-1630webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RISK
open
Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RISK
open
previouspage 459 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.