Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
ASP NEWS 3.0 - 'news_detail.asp' SQL Injection
CVE-2007-0566webappsasp
SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RISK
open
ReferênciaVexDay Proof
Drunken:Golem Portal 0.5.1 Alpha 2 - Remote File Inclusion
CVE-2007-0572webappsphp
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earli
23RISK
open
ReferênciaVexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
CVE-2007-0573webappsphp
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Foro Domus 2.10 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0580webappsphp
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0581webappsphp
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0589webappsasp
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RISK
open
ReferênciaVexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0590webappsasp
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RISK
open
ReferênciaVexDay Proof
Virtual Path 1.0 - '/vp/configure.php' Remote File Inclusion
CVE-2007-0591webappsphp
PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attack
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke Module Emporium 2.3.0 - SQL Injection
CVE-2007-1034webappsphp
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke al
23RISK
open
ReferênciaVexDay Proof
Xpression News 1.0.1 - 'archives.php' Remote File Disclosure
CVE-2007-1040webappsphp
Directory traversal vulnerability in archives.php in Xpression News (X-News) 1.0.1 allows remote attackers to include ar
23RISK
open
ReferênciaVexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
CVE-2007-1041localwindows
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1080doswindows
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RISK
open
ReferênciaVexDay Proof
PHP-MIP 0.1 - 'top.php?laypath' Remote File Inclusion
CVE-2007-1104webappsphp
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
phpBB Module NoMoKeTos Rules 0.0.1 - Remote File Inclusion
CVE-2007-1106webappsphp
PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module fo
23RISK
open
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.3.x - Blind SQL Injection
CVE-2007-1107webappsphp
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISK
open
ReferênciaVexDay Proof
CS-Gallery 2.0 - 'index.php?album' Remote File Inclusion
CVE-2007-1108webappsphp
PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote att
23RISK
open
ReferênciaVexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
CVE-2007-1130webappsphp
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Sinapis Forum 2.2 - 'sinapis.php?fuss' Remote File Inclusion
CVE-2007-1131webappsphp
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion
CVE-2007-1133webappsphp
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
CVE-2007-1163webappsphp
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
CVE-2007-1172webappsphp
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Plan 9 Kernel - 'devenv.c OTRUNC/pwrite' Local Privilege Escalation
CVE-2007-1189localplan9
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite
23RISK
open
ReferênciaVexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RISK
open
ReferênciaVexDay Proof
Rigter Portal System (RPS) 6.2 - Blind SQL Injection
CVE-2007-1293webappsphp
SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attacker
23RISK
open
ReferênciaVexDay Proof
DivX Web Player 1.3.0 - 'npdivx32.dll' Remote Denial of Service
CVE-2007-1294doswindows
A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.
23RISK
open
ReferênciaVexDay Proof
AJ Classifieds 1.0 - 'postingdetails.php' SQL Injection
CVE-2007-1296webappsphp
SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL
23RISK
open
ReferênciaVexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
CVE-2007-1297webappsphp
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
ReferênciaVexDay Proof
AJ Auction Pro - 'subcat.php' SQL Injection
CVE-2007-1298webappsphp
SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Mani Stats Reader 1.2 - 'ipath' Remote File Inclusion
CVE-2007-1299webappsphp
PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to exe
23RISK
open
previouspage 186 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.