Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Joomla! 1.5.0 Beta - 'pcltar.php' Remote File Inclusion
CVE-2007-2199webappsphp
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RISK
open
ReferênciaVexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
CVE-2007-0687webappsphp
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RISK
open
ReferênciaVexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
CVE-2007-2303webappsphp
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
CVE-2007-1061webappsphp
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISK
open
ReferênciaVexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
CVE-2007-1074localwindows
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1075doswindows
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RISK
open
ReferênciaVexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
CVE-2007-2366localwindows
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf
35RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2368webappsphp
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISK
open
ReferênciaVexDay Proof
News-Letterman 1.1 - 'eintrag.php?sqllog' Remote File Inclusion
CVE-2007-1340webappsphp
PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
CVE-2007-1375localmultiple
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
CVE-2007-2373webappsphp
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISK
open
ReferênciaVexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
CVE-2007-2711remotewindows
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RISK
open
ReferênciaVexDay Proof
Creative Files 1.2 - 'kommentare.php' SQL Injection
CVE-2007-1556webappsphp
SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
CVE-2007-1633webappsphp
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RISK
open
ReferênciaVexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
CVE-2007-2751webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
Battle.net Clan Script for PHP 1.5.1 - SQL Injection
CVE-2007-1909webappsphp
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows re
23RISK
open
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2004webappsphp
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2006webappsphp
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_yanc 1.4 Beta - 'id' SQL Injection
CVE-2007-2792webappsphp
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RISK
open
ReferênciaVexDay Proof
GeekLog 2.x - 'ImageImageMagick.php' Remote File Inclusion
CVE-2007-2793webappsphp
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitr
35RISK
open
ReferênciaVexDay Proof
Vizayn Urun Tanitim Sistemi 0.2 - 'tr' SQL Injection
CVE-2007-2803webappsasp
SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
CVE-2007-2816webappsphp
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RISK
open
ReferênciaVexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
CVE-2007-2851remotewindows
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
CVE-2007-2853remotewindows
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
CVE-2007-2854webappsphp
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RISK
open
ReferênciaVexDay Proof
PHPOracleView - 'include_all.inc.php?page_dir' Remote File Inclusion
CVE-2007-2340webappsphp
Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to
35RISK
open
ReferênciaVexDay Proof
CreaDirectory 1.2 - 'error.asp?id' SQL Injection
CVE-2007-2342webappsasp
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary S
23RISK
open
previouspage 174 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.