Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,302cataloged exploits
35,469CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Claroline 1.x - '/inc/lib/language.lib.php?language' Traversal Local File Inclusion
CVE-2007-4718webappsphp03 Sep 2007
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to inclu
23RISK
open
Exploit-DBVexDay Proof
Claroline 1.x - '/admin/advancedUserSearch.php?action' Cross-Site Scripting
CVE-2007-4717webappsphp03 Sep 2007
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RISK
open
Exploit-DBVexDay Proof
Apple QuickTime < 7.2 - SMIL Remote Integer Overflow
CVE-2007-2394dosmultiple03 Sep 2007
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to ex
28RISK
open
Exploit-DBVexDay Proof
Yahoo! Messenger - 'YVerInfo.dll 2007.8.27.1' ActiveX Buffer Overflow
CVE-2007-4515remotewindows01 Sep 2007
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo!
50RISK
open
Exploit-DBVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlaapmview.asp' Cross-Site Scripting
CVE-2007-4630webappsasp30 Aug 2007
Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to in
23RISK
open
Exploit-DBVexDay Proof
Microworld eScan (Multiple Products) - Local Privilege Escalation
CVE-2007-4649localwindows30 Aug 2007
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Ev
23RISK
open
Exploit-DBVexDay Proof
Norman Virus Control - 'nvcoaft51.sys' ioctl BF672028
CVE-2007-4648localwindows30 Aug 2007
The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa
23RISK
open
Exploit-DBVexDay Proof
Cisco CallManager 4.2 / CUCM 4.2 - Logon Page 'lang' SQL Injection
CVE-2007-4634webappsasp29 Aug 2007
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b,
23RISK
open
Exploit-DBVexDay Proof
EnterpriseDB Advanced Server 8.2 - Uninitialized Pointer
CVE-2007-4639doslinux29 Aug 2007
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to p
23RISK
open
Exploit-DBVexDay Proof
Yahoo! Messenger 8.1.0.413 - 'webcam' Remote Crash
CVE-2007-4391doswindows29 Aug 2007
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denia
23RISK
open
Exploit-DBVexDay Proof
Yahoo! Messenger 8.1 - File Transfer Denial of Service
CVE-2007-4635doswindows29 Aug 2007
Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via ce
23RISK
open
Exploit-DBVexDay Proof
Doomsday Engine 1.8.6/1.9 - Multiple Remote Vulnerabilities
CVE-2007-4642remotelinux29 Aug 2007
Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary c
28RISK
open
Exploit-DBVexDay Proof
Microsoft MSN Messenger 7.x/8.0? - Video Remote Heap Overflow
CVE-2007-2931remotewindows29 Aug 2007
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted rem
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Denial of Service (MS07-046)
CVE-2007-3034doswindows29 Aug 2007
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2,
35RISK
open
Exploit-DBVexDay Proof
ACG News 1.0 - 'index.php' Multiple SQL Injections
CVE-2007-4603webappsphp28 Aug 2007
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Microsoft MSN Messenger 8.0 - Video Conversation Buffer Overflow
CVE-2007-2931remotewindows28 Aug 2007
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted rem
35RISK
open
Exploit-DBVexDay Proof
Blizzard Entertainment StarCraft Brood War 1.15.1 - Minimap Preview Remote Denial of Service
CVE-2007-4638dosmultiple28 Aug 2007
Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (appl
23RISK
open
Exploit-DBVexDay Proof
Arcadem 2.01 - SQL Injection / Remote File Inclusion
CVE-2007-4551webappsphp27 Aug 2007
PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arb
23RISK
open
Exploit-DBVexDay Proof
Arcadem 2.01 - SQL Injection / Remote File Inclusion
CVE-2007-4552webappsphp27 Aug 2007
SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
Thomson SpeedTouch ST 2030 (SIP Phone) - Remote Denial of Service
CVE-2007-4553doshardware27 Aug 2007
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi
23RISK
open
Exploit-DBVexDay Proof
Motorola Timbuktu Pro 8.6.3.1367 - Directory Traversal
CVE-2007-4220remotewindows27 Aug 2007
Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or
23RISK
open
Exploit-DBVexDay Proof
Thomson SpeedTouch ST 2030 (SIP Phone) - SIP Invite Message Remote Denial of Service
CVE-2007-4553doshardware27 Aug 2007
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi
23RISK
open
Exploit-DBVexDay Proof
AutoIndex PHP Script 2.2.2 - 'PHP_SELF index.php' Cross-Site Scripting
CVE-2007-5983webappsphp27 Aug 2007
Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote
23RISK
open
Exploit-DBVexDay Proof
Dale Mooney Calendar Events - 'Viewevent.php' SQL Injection
CVE-2007-4611webappsphp27 Aug 2007
SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
ISC BIND 8 - Remote Cache Poisoning (1)
CVE-2007-2930remotelinux27 Aug 2007
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS q
23RISK
open
Exploit-DBVexDay Proof
ISC BIND 8 - Remote Cache Poisoning (2)
CVE-2007-2930remotelinux27 Aug 2007
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS q
23RISK
open
Exploit-DBVexDay Proof
Mercury/32 Mail Server 3.32 < 4.51 - SMTP EIP Overwrite
CVE-2004-2513remotewindows26 Aug 2007
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RISK
open
Exploit-DBVexDay Proof
Mercury/32 Mail Server 3.32 < 4.51 - SMTP EIP Overwrite
CVE-2004-1211remotewindows26 Aug 2007
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RISK
open
Exploit-DBVexDay Proof
SIDVault LDAP Server - Remote Buffer Overflow
CVE-2007-4566remotelinux25 Aug 2007
Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f
28RISK
open
Exploit-DBVexDay Proof
Vavoom 1.24 - str.cpp VStr::Resize Function Crafted UDP Packet Remote Denial of Service
CVE-2007-4535dosmultiple24 Aug 2007
The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (da
23RISK
open
previouspage 516 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.