Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
CVE-2008-1117remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISK
open
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1117remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RISK
open
ReferênciaVexDay Proof
Barryvan Compo Manager 0.3 - Remote File Inclusion
CVE-2008-1126webappsphp
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arb
28RISK
open
ReferênciaVexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
CVE-2008-1137webappsphp
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RISK
open
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - Local Kernel Ring0 link list zero SYSTEM
CVE-2008-1139localwindows
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain
23RISK
open
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
CVE-2008-1177webappsphp
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2369webappsphp
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RISK
open
ReferênciaVexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
CVE-2007-2371webappsphp
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RISK
open
ReferênciaVexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RISK
open
ReferênciaVexDay Proof
EDraw Office Viewer Component - Unsafe Method
CVE-2007-3168remotewindows
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RISK
open
ReferênciaVexDay Proof
dagger Web engine 23jan2007 - Remote File Inclusion
CVE-2007-3431webappsphp
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows r
45RISK
open
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3433webappsphp
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISK
open
ReferênciaVexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
CVE-2007-3524webappsphp
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISK
open
ReferênciaVexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
CVE-2007-3526webappsphp
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
CVE-2007-4005remotewindows
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISK
open
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISK
open
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISK
open
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISK
open
ReferênciaVexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
CVE-2007-2596webappsphp
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Monalbum 0.8.7 - Remote Code Execution
CVE-2007-2647webappsphp
Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users
23RISK
open
ReferênciaVexDay Proof
BlogMe 3.0 - 'archshow.asp?var' SQL Injection
CVE-2007-2661webappsasp
SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
CVE-2007-3360remotelinux
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RISK
open
ReferênciaVexDay Proof
SonicWALL SSL-VPN - 'NeLaunchCtrl' ActiveX Control Remote Command Execution
CVE-2007-5603remotewindows
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RISK
open
ReferênciaVexDay Proof
Sony CONNECT Player 4.x - '.m3u' Local Stack Overflow
CVE-2007-5709localwindows
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code
28RISK
open
ReferênciaVexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
CVE-2007-5720webappsphp
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RISK
open
ReferênciaVexDay Proof
Jakarta Slide 2.1 RC1 - Remote File Disclosure
CVE-2007-5731remotemultiple
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read
23RISK
open
ReferênciaVexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
CVE-2007-4377remotewindows
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RISK
open
previouspage 176 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.