Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,107cataloged exploits
34,679CVEs with public exploitation
24,695lab-tested
21,692 exploits
Referência
CVE-2009-4989
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbit
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin myflash 1.00 - 'wppath' Remote File Inclusion
CVE-2007-2485webappsphp
PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allow
35RISK
open
ReferênciaVexDay Proof
PostNuke Module v4bJournal - SQL Injection
CVE-2007-2492webappsphp
SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to exec
23RISK
open
ReferênciaVexDay Proof
Excel Viewer OCX 3.1.0.6 - Multiple Denial of Service Vulnerabilities
CVE-2007-2495doswindows
Multiple stack-based buffer overflows in the ExcelOCX ActiveX control in ExcelViewer.ocx 3.1.0.6 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
1024 CMS 0.7 - 'download.php' Remote File Disclosure
CVE-2007-2507webappsphp
Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to rea
23RISK
open
ReferênciaVexDay Proof
Berylium2 2003-08-18 - 'beryliumroot' Remote File Inclusion
CVE-2007-2531webappsphp
PHP remote file inclusion vulnerability in berylium-classes.php in Berylium2 2003-08-18 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
workbench 0.11 - 'header.php?path' Remote File Inclusion
CVE-2007-2542webappsphp
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
CVE-2007-2544webappsphp
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RISK
open
Referência
CVE-2007-2583
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RISK
open
Referência
CVE-2010-1952
Directory traversal vulnerability in the BeeHeard (com_beeheard) and BeeHeard Lite (com_beeheardlite) component 1.0 for
43RISK
open
ReferênciaVexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
CVE-2007-2596webappsphp
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
telltarget 1.3.3 - 'tt_docroot' Remote File Inclusion
CVE-2007-2597webappsphp
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary P
28RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2599webappsphp
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2600webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RISK
open
ReferênciaVexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
CVE-2007-2608webappsphp
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
CVE-2007-2615webappsphp
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RISK
open
Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RISK
open
ReferênciaVexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
CVE-2007-2620webappsphp
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RISK
open
ReferênciaVexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2709webappsphp
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
CVE-2007-2715webappsphp
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RISK
open
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
CVE-2007-2749webappsphp
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
CVE-2007-2751webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RISK
open
ReferênciaVexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RISK
open
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
CVE-2007-2777webappsphp
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RISK
open
ReferênciaVexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
CVE-2007-2779webappsphp
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISK
open
previouspage 291 / 724next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.