Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
Referência
CVE-2017-17585
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISK
open
ReferênciaVexDay Proof
Web Slider 0.6 - 'path' Remote File Inclusion
CVE-2007-2067webappsphp
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote a
23RISK
open
Referência
CVE-2017-17585
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RISK
open
ReferênciaVexDay Proof
StoreFront for Gallery - 'GALLERY_BASEDIR' Remote File Inclusion
CVE-2007-2068webappsphp
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
openMairie 1.10 - '/scr/soustab.php' Local File Inclusion
CVE-2007-2069webappsphp
Directory traversal vulnerability in scr/soustab.php in openMairie 1.11 and earlier allows remote attackers to include a
23RISK
open
ReferênciaVexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
CVE-2007-2070webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RISK
open
ReferênciaVexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
CVE-2007-2091webappsphp
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RISK
open
ReferênciaVexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
CVE-2007-2141webappsphp
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RISK
open
Referência
CVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Template Be2004-2 - 'index.php' Remote File Inclusion
CVE-2007-2143webappsphp
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to exe
23RISK
open
Referência
CVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RISK
open
ReferênciaVexDay Proof
Joomla! Component JoomlaPack 1.0.4a2 RE - 'CAltInstaller.php' Remote File Inclusion
CVE-2007-2144webappsphp
PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component
23RISK
open
ReferênciaVexDay Proof
Cabron Connector 1.1.0-Full - Remote File Inclusion
CVE-2007-2154webappsphp
PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote
23RISK
open
Referência
CVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RISK
open
ReferênciaVexDay Proof
Rezervi 0.9 - 'root' Remote File Inclusion
CVE-2007-2156webappsphp
Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PH
28RISK
open
ReferênciaVexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
CVE-2007-2167webappsphp
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RISK
open
Referência
CVE-2017-17588
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RISK
open
ReferênciaVexDay Proof
Mozzers SubSystem final - 'subs.php' Remote Code Execution
CVE-2007-2169webappsphp
Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into
23RISK
open
ReferênciaVexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
CVE-2007-2180doswindows
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RISK
open
ReferênciaVexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
CVE-2007-2181webappsphp
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
CVE-2007-2183webappsphp
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Supasite 1.23b - Multiple Remote File Inclusions
CVE-2007-2185webappsphp
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP cod
23RISK
open
Referência
Microsoft Windows 11 - Kernel Privilege Escalation
CVE-2024-21338HIGHunder attackransomwarelocalwindows
Windows Kernel Elevation of Privilege Vulnerability
83RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2368webappsphp
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISK
open
Referência
CVE-2017-17592
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2369webappsphp
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open
Referência
CVE-2017-17592
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
CVE-2007-2371webappsphp
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open
Referência
CVE-2024-22318
IBM i Access Client Solutions information disclosure
33RISK
open
ReferênciaVexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
CVE-2007-2471webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RISK
open
previouspage 460 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.