Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'Log.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'Event.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'UserType.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'user.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'UrlType.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'topic.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'TimeUnit.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'template.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'SystemPref.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'SubscriptionSection.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - '/implementation/Management/configuration.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'image.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'IPAccess.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'issue.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'SubscriptionDefaultTime.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - '/implementation/Management/db_connect.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'article.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Campsite 2.6.1 - 'ArticleData.php?g_documentRoot' Remote File Inclusion
CVE-2006-5911webappsphp08 May 2007
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
SmartCode VNC Manager 3.6 - 'scvncctrl.dll' Denial of Service
CVE-2007-2526doswindows08 May 2007
Heap-based buffer overflow in the ConnectAsyncEx function in VNC Viewer ActiveX control (scvncctrl.dll) in the SmartCode
23RISK
open
Exploit-DBVexDay Proof
FipsCMS 2.1 - 'pid' SQL Injection
CVE-2007-2561webappsasp07 May 2007
SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
SunShop Shopping Cart 4.0 - 'index.php' Multiple SQL Injections
CVE-2007-2549webappsphp07 May 2007
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
OTRS 2.0.4 - index.pl Cross-Site Scripting
CVE-2007-2524webappscgi07 May 2007
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
SunShop Shopping Cart 4.0 - 'index.php?l' Cross-Site Scripting
CVE-2007-2547webappsphp07 May 2007
Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
PHP PEAR 1.5.3 - INSTALL-AS Attribute Arbitrary File Overwrite
CVE-2007-2519remotelinux07 May 2007
Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to ov
23RISK
open
Exploit-DBVexDay Proof
ELinks Relative 0.10.6/011.1 - Path Arbitrary Code Execution
CVE-2007-2027locallinux07 May 2007
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.
23RISK
open
Exploit-DBVexDay Proof
Versalsoft HTTP File Uploader - ActiveX 6.36 AddFile Remote Denial of Service
CVE-2007-2563doswindows07 May 2007
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remot
23RISK
open
Exploit-DBVexDay Proof
Trend Micro ServerProtect 5.58 - 'SpntSvc.exe' Remote Stack Buffer Overflow
CVE-2007-2508remotewindows07 May 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RISK
open
Exploit-DBVexDay Proof
Microsoft SharePoint Server 3.0 - Cross-Site Scripting
CVE-2007-2581remotewindows04 May 2007
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003
35RISK
open
Exploit-DBVexDay Proof
ZOO - '.ZOO' Decompression Infinite Loop Denial of Service (PoC)
CVE-2007-1669dosmultiple04 May 2007
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virus
28RISK
open
Exploit-DBVexDay Proof
Net Portal Dynamic System (NPDS) 5.10 - Remote Code Execution (2)
CVE-2007-2537webappsphp04 May 2007
Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to exec
23RISK
open
previouspage 532 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.