Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Boa 0.93.15 - Administrator Password Overwrite Authentication Bypass
CVE-2007-4915doslinux14 Sep 2007
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RISK
open
Exploit-DBVexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
CVE-2007-3974webappsphp14 Sep 2007
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RISK
open
Exploit-DBVexDay Proof
HP - ActiveX 'hpqutil.dll' ListFiles Remote Heap Overflow (PoC)
CVE-2007-4916doswindows14 Sep 2007
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC
28RISK
open
Exploit-DBVexDay Proof
WinSCP 4.0.3 - URL Protocol Handler Arbitrary File Access
CVE-2007-4909remotewindows13 Sep 2007
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote
23RISK
open
Exploit-DBVexDay Proof
GForge < 4.6b2 - 'skill_delete' SQL Injection
CVE-2007-3913webappsphp13 Sep 2007
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecifi
23RISK
open
Exploit-DBVexDay Proof
KMPlayer 2.9.3.1214 - Multiple Remote Denial of Service Vulnerabilities
CVE-2007-4941doslinux12 Sep 2007
KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file w
23RISK
open
Exploit-DBVexDay Proof
CS-Guestbook 0.1 - Login Credentials Information Disclosure
CVE-2007-4937webappsphp12 Sep 2007
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attac
23RISK
open
Exploit-DBVexDay Proof
MPlayer 1.0 - AVIHeader.C Heap Buffer Overflow
CVE-2007-4938doslinux12 Sep 2007
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a de
28RISK
open
Exploit-DBVexDay Proof
BOINC 5.10.20 - 'text_search_action.php?search_string' Cross-Site Scripting
CVE-2007-4899webappsphp12 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Media Player Classic 6.4.9 - Malformed AVI Header Multiple Remote Vulnerabilities
CVE-2007-4939doslinux12 Sep 2007
Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in
28RISK
open
Exploit-DBVexDay Proof
BOINC 5.10.20 - 'forum_forum.php?id' Cross-Site Scripting
CVE-2007-4899webappsphp12 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
SWSoft Plesk 8.2 - 'login.php3' PLESKSESSID Cookie SQL Injection
CVE-2007-4892webappsphp12 Sep 2007
Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
Microsoft Agent - 'agentdpv.dll' ActiveX Control Malformed URL Stack Buffer Overflow
CVE-2007-3040remotewindows11 Sep 2007
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to
35RISK
open
Exploit-DBVexDay Proof
CellFactor REvolution 1.03 - Multiple Remote Code Execution Vulnerabilities
CVE-2007-4838dosmultiple10 Sep 2007
Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4942webappsphp08 Sep 2007
PHP remote file inclusion vulnerability in modules/Discipline/StudentFieldBreakdown.php in Focus/SIS 1.0 allows remote a
23RISK
open
Exploit-DBVexDay Proof
Toms Gastebuch 1.00/1.01 - 'header.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-4896webappsphp08 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote
23RISK
open
Exploit-DBVexDay Proof
Toms Gästebuch 1.00 - '/admin/header.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-4711webappsphp07 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Toms Gästebuch 1.00 - 'form.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-4711webappsphp07 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Toms Gaestebuch 1.00 allow remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Trend Micro ServerProtect - 'eng50.dll' Remote Stack Overflow
CVE-2007-1070remotewindows06 Sep 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance F
60RISK
open
Exploit-DBVexDay Proof
Unreal Commander 0.92 - Directory Traversal
CVE-2007-4843remotewindows06 Sep 2007
Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to creat
23RISK
open
Exploit-DBVexDay Proof
Alien Arena 2007 6.10 - Multiple Remote Vulnerabilities
CVE-2007-4754dosmultiple05 Sep 2007
Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier al
23RISK
open
Exploit-DBVexDay Proof
Apache Tomcat 5.5.15 - cal2.jsp Cross-Site Scripting
CVE-2006-7196webappsjsp04 Sep 2007
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0
45RISK
open
Exploit-DBVexDay Proof
AkkyWareHOUSE '7-zip32.dll' 4.42 - Heap Buffer Overflow
CVE-2007-4725remotewindows04 Sep 2007
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before
23RISK
open
Exploit-DBVexDay Proof
Move Media Player 1.0 Quantum Streaming - ActiveX Control Multiple Buffer Overflow Vulnerabilities
CVE-2007-4722remotewindows04 Sep 2007
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RISK
open
Exploit-DBVexDay Proof
E-Smart Cart 1.0 - 'login.asp' SQL Injection
CVE-2007-4762webappsasp04 Sep 2007
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
212Cafe WebBoard 6.30 - 'Read.php' SQL Injection
CVE-2007-4719webappsphp04 Sep 2007
SQL injection vulnerability in read.php in 212cafeBoard 6.30 Beta allows remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.x - '/admin/advancedUserSearch.php?action' Cross-Site Scripting
CVE-2007-4717webappsphp03 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.x - '/admin/campusProblem.php?view' Cross-Site Scripting
CVE-2007-4717webappsphp03 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RISK
open
Exploit-DBVexDay Proof
Apple QuickTime < 7.2 - SMIL Remote Integer Overflow
CVE-2007-2394dosmultiple03 Sep 2007
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to ex
28RISK
open
Exploit-DBVexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
CVE-2007-4738webappsphp03 Sep 2007
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
28RISK
open
previouspage 515 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.