Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
22,367 exploits
ReferênciaVexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RISK
open
Referência
CVE-2017-17620
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RISK
open
ReferênciaVexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
CVE-2007-3289webappsphp
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3290webappsphp
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3292webappsphp
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISK
open
ReferênciaVexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
CVE-2007-3306webappsphp
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISK
open
Referência
CVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open
ReferênciaVexDay Proof
Solar Empire 2.9.1.1 - Blind SQL Injection / Hash Retrieve
CVE-2007-3307webappsphp
SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
LAN Management System (LMS) 1.9.6 - Remote File Inclusion
CVE-2007-3325webappsphp
PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remo
35RISK
open
ReferênciaVexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
CVE-2007-3360remotelinux
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RISK
open
ReferênciaVexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
CVE-2007-3370webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISK
open
Referência
CVE-2026-18581
ggml-org llama.cpp Jinja Minja Template parser.cpp assertion
33RISK
open
ReferênciaVexDay Proof
NCTAudioEditor2 ActiveX DLL 'NCTWMAFile2.dll 2.6.2.157' - File Write
CVE-2007-3400remotewindows
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.
23RISK
open
ReferênciaVexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
CVE-2007-3401webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISK
open
Referência
CVE-2026-14864
JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode
33RISK
open
Referência
CVE-2026-14841
King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget
33RISK
open
Referência
CVE-2026-67298
FreeRDP 3.28.0 Heap Buffer Overflow via RAIL orderLength Underflow
41RISK
open
Referência
CVE-2026-67288
FreeRDP before 3.29.0 Denial of Service via smartcard cache
41RISK
open
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3448webappsphp
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers t
23RISK
open
Referência
CVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open
ReferênciaVexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3449webappsphp
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the n
23RISK
open
ReferênciaVexDay Proof
EVA-Web 1.1 < 2.2 - 'index.php3' Remote File Inclusion
CVE-2007-3460webappsphp
Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to ex
23RISK
open
Referência
CVE-2017-17621
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RISK
open
ReferênciaVexDay Proof
dagger Web engine 23jan2007 - Remote File Inclusion
CVE-2007-3431webappsphp
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows r
45RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3433webappsphp
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISK
open
Referência
CVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open
ReferênciaVexDay Proof
Sony Network Camera SNC-P5 1.0 - ActiveX viewer Heap Overflow (PoC)
CVE-2007-3488doswindows
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5
28RISK
open
Referência
CVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RISK
open
ReferênciaVexDay Proof
Microsoft Excel 2000/2003 - Sheet Name (PoC)
CVE-2007-3490doswindows
Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified
35RISK
open
previouspage 463 / 746next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.