Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
STWC-Counter 3.4.0 - 'downloadcounter.php' Remote File Inclusion
CVE-2007-1233webappsphp
PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attacke
23RISK
open
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RISK
open
ReferênciaVexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
CVE-2007-1260remotewindows
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
SonicMailer Pro 3.2.3 - 'index.php' SQL Injection
CVE-2007-1425webappsphp
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
CVE-2007-1427webappsphp
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
23RISK
open
ReferênciaVexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
CVE-2007-1480webappsphp
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php
23RISK
open
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1481webappsphp
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i
23RISK
open
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1482webappsphp
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RISK
open
ReferênciaVexDay Proof
WebLog - 'index.php' Remote File Disclosure
CVE-2007-1487webappsphp
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RISK
open
ReferênciaVexDay Proof
Avant Browser 11.0 build 26 - Remote Stack Overflow Crash
CVE-2007-1501doswindows
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash)
23RISK
open
ReferênciaVexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
CVE-2019-11537webappsphp
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISK
open
ReferênciaVexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
CVE-2006-5022webappsphp
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISK
open
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISK
open
ReferênciaVexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
CVE-2007-1630webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
CVE-2007-1640webappsphp
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
CVE-2007-1641webappsphp
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
CVE-2007-1696webappsasp
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
CVE-2007-1698webappsphp
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RISK
open
ReferênciaVexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
CVE-2007-1702webappsphp
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RISK
open
ReferênciaVexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
CVE-2007-1703webappsphp
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RISK
open
ReferênciaVexDay Proof
Active Trade 2 - 'catid' SQL Injection
CVE-2007-1705webappsasp
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
ReferênciaVexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
CVE-2007-1706webappsasp
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
CVE-2007-1708webappsphp
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
CVE-2007-1735localwindows
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
CVE-2007-1998webappsphp
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
CVE-2006-5923webappsphp
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RISK
open
ReferênciaVexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
CVE-2007-1937webappsphp
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
XOOPS Module Rha7 Downloads 1.0 - 'visit.php' SQL Injection
CVE-2007-1960webappsphp
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other
23RISK
open
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.3 - Remote Code Execution
CVE-2007-1963webappsphp
SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and
23RISK
open
ReferênciaVexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
CVE-2007-1974webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RISK
open
previouspage 187 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.