Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,618cataloged exploits
35,646CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
PrecisionID Barcode ActiveX 1.9 - Remote Denial of Service
CVE-2007-2744doswindows16 May 2007
Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote atta
23RISK
open
Exploit-DBVexDay Proof
Computer Associates BrightStor ARCserve Backup 11.5 - mediasvr caloggerd Denial of Service
CVE-2007-5332doswindows16 May 2007
Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R1
23RISK
open
Exploit-DBVexDay Proof
Caucho Resin 3.1 - '/web-inf' Traversal Arbitrary File Access
CVE-2007-2440remotewindows15 May 2007
Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allo
23RISK
open
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - '/view/search/?path' Cross-Site Scripting
CVE-2007-2732webappsphp15 May 2007
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
DeWizardX - 'DEWizardAX.ocx' Arbitrary File Overwrite
CVE-2007-2725remotewindows15 May 2007
The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary fil
23RISK
open
Exploit-DBVexDay Proof
Jetbox CMS 2.1 Email - 'FormMail.php' Input Validation
CVE-2007-1898webappsphp15 May 2007
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTING
23RISK
open
Exploit-DBVexDay Proof
Caucho Resin 3.1 - Encoded Space Request Full Path Disclosure
CVE-2007-2441remotewindows15 May 2007
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the sys
23RISK
open
Exploit-DBVexDay Proof
XOOPS Module MyConference 1.0 - 'index.php' SQL Injection
CVE-2007-2737webappsphp15 May 2007
SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Vista - Forged ARP packet Network Stack Denial of Service
CVE-2007-1531doswindows15 May 2007
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to
28RISK
open
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - view/supplynews Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-2732webappsphp15 May 2007
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
SonicBB 1.0 - Multiple SQL Injections
CVE-2007-1902webappsphp14 May 2007
Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (
23RISK
open
Exploit-DBVexDay Proof
SonicBB 1.0 - 'search.php' Cross-Site Scripting
CVE-2007-1903webappsphp14 May 2007
Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Clever Database Comparer ActiveX 2.2 - Remote Buffer Overflow (PoC)
CVE-2007-2648doswindows14 May 2007
Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2710webappsphp14 May 2007
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote atta
23RISK
open
Exploit-DBVexDay Proof
WordPress Plugin Akismet 2.1.3 - Cross-Site Scripting
CVE-2007-2714webappsphp14 May 2007
Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact
28RISK
open
Exploit-DBVexDay Proof
Samba 3.0.21 < 3.0.24 - LSA trans names Heap Overflow (Metasploit)
CVE-2007-2446remotelinux14 May 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RISK
open
Exploit-DBVexDay Proof
webdesproxy 0.0.1 - 'exec-shield' GET Remote Code Execution
CVE-2007-2668remotelinux14 May 2007
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involvin
23RISK
open
Exploit-DBVexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
CVE-2005-2412webappsphp12 May 2007
PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP c
23RISK
open
Exploit-DBVexDay Proof
EQdkp 1.3.1 - Cross-Site Scripting
CVE-2007-2716webappsphp12 May 2007
Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
CommuniGate Pro 5.1.8 - Web Mail HTML Injection
CVE-2007-2718webappsphp12 May 2007
Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using
28RISK
open
Exploit-DBVexDay Proof
LibEXIF 0.6.x - Exif_Data_Load_Data_Entry Remote Integer Overflow
CVE-2007-2645doslinux11 May 2007
Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted
28RISK
open
Exploit-DBVexDay Proof
TFTP Server TFTPDWin 0.4.2 - Directory Traversal
CVE-2007-2639remotewindows11 May 2007
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside th
23RISK
open
Exploit-DBVexDay Proof
PHP Multi User Randomizer 2006.09.13 - 'Configure_Plugin.TPL.php' Cross-Site Scripting
CVE-2007-2632webappsphp10 May 2007
Multiple cross-site scripting (XSS) vulnerabilities in PHP Multi User Randomizer (phpMUR) 2006.09.13 allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Sun Microsystems Solaris SRSEXEC 3.2.x - Arbitrary File Read Local Information Disclosure
CVE-2007-2617localsolaris10 May 2007
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
38RISK
open
Exploit-DBVexDay Proof
McAfee Security Center IsOldAppInstalled - ActiveX Buffer Overflow
CVE-2007-2584remotewindows10 May 2007
Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMG
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - Arbitrary File Rewrite (MS07-027)
CVE-2007-2221remotewindows10 May 2007
Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Expl
35RISK
open
Exploit-DBVexDay Proof
GIMP 2.2.14 (Windows x86) - '.ras' Download/Execute Buffer Overflow
CVE-2007-2356localwindows_x8609 May 2007
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-
28RISK
open
Exploit-DBVexDay Proof
Barcodewiz ActiveX Control 2.0 - 'Barcodewiz.dll' Remote Buffer Overflow (PoC)
CVE-2007-2585doswindows09 May 2007
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allow
23RISK
open
Exploit-DBVexDay Proof
Barcodewiz ActiveX Control 2.52 - 'Barcodewiz.dll' Overwrite (SEH)
CVE-2007-2585remotewindows09 May 2007
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allow
23RISK
open
Exploit-DBVexDay Proof
GDivX Zenith Player AviFixer Class - 'fix.dll 1.0.0.1' Buffer Overflow (PoC)
CVE-2009-3967doswindows09 May 2007
SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar
23RISK
open
previouspage 530 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.