Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
22,429 exploits
ReferênciaVexDay Proof
Papoo 3.02 - kontakt menuid SQL Injection
CVE-2007-2320webappsphp
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
JulmaCMS 1.4 - 'file.php' Remote File Disclosure
CVE-2007-2324webappsphp
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (
23RISK
open
ReferênciaVexDay Proof
PHPOracleView - 'include_all.inc.php?page_dir' Remote File Inclusion
CVE-2007-2340webappsphp
Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to
35RISK
open
ReferênciaVexDay Proof
CreaDirectory 1.2 - 'error.asp?id' SQL Injection
CVE-2007-2342webappsasp
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
CodeWand phpBrowse - 'site_path' Remote File Inclusion
CVE-2007-2345webappsphp
PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers
23RISK
open
ReferênciaVexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
CVE-2007-2364webappsphp
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RISK
open
Referência
CVE-2018-10710
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RISK
open
Referência
CVE-2018-12055
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
CVE-2007-2373webappsphp
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISK
open
ReferênciaVexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
CVE-2007-2471webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
CVE-2007-2481webappsphp
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh
35RISK
open
Referência
CVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
CVE-2007-2483webappsphp
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
CVE-2007-2484webappsphp
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress,
35RISK
open
Referência
CVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin myflash 1.00 - 'wppath' Remote File Inclusion
CVE-2007-2485webappsphp
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow
35RISK
open
ReferênciaVexDay Proof
PostNuke Module v4bJournal - SQL Injection
CVE-2007-2492webappsphp
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to exec
23RISK
open
ReferênciaVexDay Proof
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
CVE-2007-2495doswindows
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
1024 CMS 0.7 - 'download.php' Remote File Disclosure
CVE-2007-2507webappsphp
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to rea
23RISK
open
Referência
CVE-2017-17595
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RISK
open
ReferênciaVexDay Proof
Berylium2 2003-08-18 - 'beryliumroot' Remote File Inclusion
CVE-2007-2531webappsphp
PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
workbench 0.11 - 'header.php?path' Remote File Inclusion
CVE-2007-2542webappsphp
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
XOOPS Flashgames Module 1.0.1 - SQL Injection
CVE-2007-2543webappsphp
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
ACGVAnnu 1.3 - 'acgv.php?rubrik' Local File Inclusion
CVE-2007-2560webappsphp
Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
CVE-2007-2751webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
Referência
CVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RISK
open
Referência
CVE-2004-2502
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISK
open
Referência
CVE-2024-6244
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RISK
open
previouspage 515 / 748next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.