Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
JSPWiki 2.5.139 - 'Diff.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5120webappsjsp25 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
JSPWiki 2.5.139 - 'NewGroup.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5120webappsjsp25 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Urchin 5.7.x - 'session.cgi' Cross-Site Scripting
CVE-2007-5112webappscgi24 Sep 2007
Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allow
23RISK
open
Exploit-DBVexDay Proof
Ask.com/AskJeeves Toolbar Toolbar 4.0.2.53 - ActiveX Remote Buffer Overflow
CVE-2007-5108remotewindows24 Sep 2007
Unspecified vulnerability in IAC Search & Media ask.com toolbar has unknown impact and remote attack vectors. NOTE: thi
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.0 - 'wp-register.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5105webappsphp22 Sep 2007
Cross-site scripting (XSS) vulnerability in wp-register.php in WordPress 2.0 and 2.0.1 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Xen 3.0.3 - pygrub TOOLS/PYGRUB/SRC/GRUBCONF.PY Local Command Injection
CVE-2007-4993locallinux22 Sep 2007
pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privil
23RISK
open
Exploit-DBVexDay Proof
XCMS 1.1/1.7 - 'Password' Arbitrary PHP Code Execution
CVE-2007-5060webappsphp22 Sep 2007
Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allow
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - ALSA snd-page-alloc Local Proc File Information Disclosure
CVE-2007-4571locallinux21 Sep 2007
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux ker
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Ptrace Privilege Escalation
CVE-2007-4573locallinux21 Sep 2007
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64
23RISK
open
Exploit-DBVexDay Proof
Xunlei Web Thunder 5.6.9.344 - ActiveX Control DownURL2 Method Remote Buffer Overflow
CVE-2007-5064remotewindows20 Sep 2007
Buffer overflow in a certain ActiveX control in Xunlei Web Thunder 5.6.9.344, possibly the DapPlayer ActiveX control in
23RISK
open
Exploit-DBVexDay Proof
WebBatch - 'webbatch.exe' Cross-Site Scripting
CVE-2007-5010webappscgi20 Sep 2007
Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via
23RISK
open
Exploit-DBVexDay Proof
Google Mini Search Appliance 3.4.14 - 'IE' Cross-Site Scripting
CVE-2007-5255remotemultiple20 Sep 2007
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance 3.4.14 allows remote attackers to inject arbitr
23RISK
open
Exploit-DBVexDay Proof
Vigile CMS 1.8 Wiki Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5052webappsphp20 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Vigile CMS 1.8 allow remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
WebBatch - 'webbatch.exe?dumpinputdata' Remote Information Disclosure
CVE-2007-5011webappscgi20 Sep 2007
webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.
23RISK
open
Exploit-DBVexDay Proof
LevelOne WBR3404TX Broadband Router - 'RC' Cross-Site Scripting
CVE-2007-5027webappscgi19 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadb
23RISK
open
Exploit-DBVexDay Proof
Alcatel-Lucent OmniPCX Enterprise 7.1 - Remote Command Execution
CVE-2007-3010CRITICALunder attackwebappscgi17 Sep 2007
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RISK
open
Exploit-DBVexDay Proof
WinImage 8.0/8.10 - File Handling Traversal Arbitrary File Overwrite
CVE-2007-4962remotewindows17 Sep 2007
Directory traversal vulnerability in WinImage 8.10 and earlier allows user-assisted remote attackers to create or overwr
23RISK
open
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.12 - 'referer' Cross-Site Scripting
CVE-2007-4977webappsphp17 Sep 2007
Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote
23RISK
open
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.12 - 'log' Local File Inclusion
CVE-2007-4976webappsphp17 Sep 2007
Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote auth
23RISK
open
Exploit-DBVexDay Proof
b1gMail 6.3.1 - 'hilfe.php' Cross-Site Scripting
CVE-2007-4975webappsphp17 Sep 2007
Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
Alcatel-Lucent OmniPCX Enterprise Communication Server 7.1 - masterCGI Command Injection (Metasploit)
CVE-2007-3010CRITICALunder attackwebappscgi17 Sep 2007
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RISK
open
Exploit-DBVexDay Proof
ewire Payment Client 1.60/1.70 - Command Execution
CVE-2007-4925webappsphp17 Sep 2007
The ewirePC_Decrypt function in ewirepcfunctions.php in eWire Payment Client (ePC) 1.60 and 1.70 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Python 2.2 ImageOP Module - Multiple Integer Overflow Vulnerabilities
CVE-2007-4965dosmultiple17 Sep 2007
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause
28RISK
open
Exploit-DBVexDay Proof
WinImage 8.0/8.10 - '.IMG' File BPB_BytsPerSec Field Denial of Service
CVE-2007-4964doswindows17 Sep 2007
WinImage 8.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via an invalid BPB_BytsPe
23RISK
open
Exploit-DBVexDay Proof
Boa 0.93.15 - Administrator Password Overwrite Authentication Bypass
CVE-2007-4915doslinux14 Sep 2007
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RISK
open
Exploit-DBVexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
CVE-2007-3974webappsphp14 Sep 2007
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RISK
open
Exploit-DBVexDay Proof
HP - ActiveX 'hpqutil.dll' ListFiles Remote Heap Overflow (PoC)
CVE-2007-4916doswindows14 Sep 2007
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC
28RISK
open
Exploit-DBVexDay Proof
Microsoft MFC Library - CFileFind::FindFile Buffer Overflow
CVE-2007-4916doswindows14 Sep 2007
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC
28RISK
open
Exploit-DBVexDay Proof
PHP-Stats 0.1.9.2 - 'Tracking.php' Cross-Site Scripting
CVE-2007-4917webappsphp14 Sep 2007
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
Axis Communications 207W Network Camera - Web Interface axis-cgi/admin/restart.cgi Cross-Site Request Forgery
CVE-2007-4930webappscgi14 Sep 2007
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 207W camera allow remote attackers to perform cer
23RISK
open
previouspage 514 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.