Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
CVE-2019-12840remotelinux
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISK
open
ReferênciaVexDay Proof
Guestbara 1.2 - Change Admin Login and Password
CVE-2007-1553webappsphp
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of
23RISK
open
ReferênciaVexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
CVE-2007-1566webappsasp
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (1)
CVE-2007-1568remotewindows
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (2)
CVE-2007-1568remotewindows
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
News Bin Pro 4.32 - Article Grabbing Remote Unicode Buffer Overflow
CVE-2007-1569doswindows
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
CVE-2007-1578doswindows_x86
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RISK
open
ReferênciaVexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
CVE-2007-1579remotewindows
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISK
open
ReferênciaVexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
CVE-2007-1613webappsphp
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Lyrics 2.0 - 'index.php?recid' SQL Injection
CVE-2007-1616webappsphp
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1617webappsphp
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
ScriptMagix Photo Rating 2.0 - SQL Injection
CVE-2007-1619webappsphp
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
CVE-2007-1620webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RISK
open
ReferênciaVexDay Proof
Active Photo Gallery - 'catid' SQL Injection
CVE-2007-1629webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open
ReferênciaVexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
CVE-2007-1630webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
CVE-2007-1640webappsphp
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
CVE-2007-1641webappsphp
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
CVE-2007-1696webappsasp
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
CVE-2007-1698webappsphp
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RISK
open
ReferênciaVexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
CVE-2007-1702webappsphp
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
CVE-2007-1703webappsphp
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RISK
open
ReferênciaVexDay Proof
Active Trade 2 - 'catid' SQL Injection
CVE-2007-1705webappsasp
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
CVE-2007-1706webappsasp
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
CVE-2007-1708webappsphp
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
CVE-2007-1735localwindows
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module Eve-Nuke 0.1 - 'mysql.php' Remote File Inclusion
CVE-2007-1778webappsphp
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remot
23RISK
open
ReferênciaVexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
CVE-2007-1790webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
CVE-2007-1791webappsphp
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISK
open
previouspage 138 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.