Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/list_members.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/membership_pricing.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/send_email.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/include/config.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/include/db_config.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/add_category.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/add_news.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/couple_milestone.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/couple_profile.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/delete_category.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/index.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/login.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/user_catelog_password.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/user_email.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/user_extend.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/user_membership_password.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Edit-X - 'Edit_Address.php' Remote File Inclusion
CVE-2007-0190webappsphp09 Jan 2007
PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - Apple Finder DMG Volume Name Memory Corruption (PoC)
CVE-2007-0197dososx09 Jan 2007
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly e
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/upload_photo.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/register.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/logout.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
iPlanet Web Server 4.1 - Search Module Cross-Site Scripting
CVE-2007-0183remotemultiple09 Jan 2007
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
MediaWiki 1.x - 'AJAX index.php' Cross-Site Scripting
CVE-2007-0177webappsphp09 Jan 2007
Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.
23RISK
open
Exploit-DBVexDay Proof
FileCOPA FTP Server 1.01 - 'LIST' Remote Buffer Overflow (Metasploit)
CVE-2006-3726remotewindows09 Jan 2007
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to
50RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/add_templates.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/admin_email.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/admin/add_welcome_text.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 Jan 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RISK
open
Exploit-DBVexDay Proof
PHPKit 1.6.1 - 'comment.php' SQL Injection
CVE-2007-0179webappsphp09 Jan 2007
SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Sun Solaris 9 - RPC Request Denial of Service
CVE-2007-0165dossolaris09 Jan 2007
Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash)
23RISK
open
Exploit-DBVexDay Proof
Novell Access Manager 3 Identity Server - 'IssueInstant' Cross-Site Scripting
CVE-2007-0110remotenovell08 Jan 2007
Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 all
23RISK
open
previouspage 553 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.