Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
22,407 exploits
Referência
CVE-2026-15230
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
41RISK
open
Referência
CVE-2026-14553
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
41RISK
open
Referência
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
28RISK
open
Referência
CVE-2026-16993
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory
28RISK
open
Referência
CVE-2026-16981
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
33RISK
open
Referência
CVE-2026-16968
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
33RISK
open
Referência
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RISK
open
ReferênciaVexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RISK
open
ReferênciaVexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RISK
open
ReferênciaVexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
CVE-2007-3118webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Kartli Alisveris Sistemi 1.0 - SQL Injection
CVE-2007-3119webappsasp
SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote at
23RISK
open
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RISK
open
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3139webappsphp
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow (2)
CVE-2007-3148remotewindows
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
28RISK
open
ReferênciaVexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
CVE-2007-3221webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RISK
open
ReferênciaVexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
CVE-2007-3230webappsphp
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RISK
open
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3235webappsphp
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISK
open
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RISK
open
ReferênciaVexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
CVE-2007-3236webappsphp
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISK
open
ReferênciaVexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
CVE-2007-3237webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISK
open
Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RISK
open
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RISK
open
Referência
CVE-2017-17620
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RISK
open
ReferênciaVexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
CVE-2007-3289webappsphp
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3290webappsphp
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISK
open
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3292webappsphp
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISK
open
ReferênciaVexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
CVE-2007-3306webappsphp
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISK
open
previouspage 532 / 747next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.