Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
ACDSee 9.0 Photo Manager - Multiple '.BMP' Denial of Service Vulnerabilities
CVE-2007-1943doswindows04 Apr 2007
Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibl
23RISK
open
Exploit-DBVexDay Proof
IrfanView 3.99 - Multiple .BMP Denial of Service Vulnerabilities
CVE-2007-1948doswindows04 Apr 2007
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute a
23RISK
open
Exploit-DBVexDay Proof
HP Mercury Quality Center - Spider90.ocx ProgColor Overflow
CVE-2007-1819remotewindows04 Apr 2007
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for M
50RISK
open
Exploit-DBVexDay Proof
phpMyNewsletter 0.6.10 - 'customize.php' Remote File Inclusion
CVE-2002-1887webappsphp04 Apr 2007
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
TrueCrypt 4.3 - 'setuid' Local Privilege Escalation
CVE-2007-1738localwindows04 Apr 2007
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) o
23RISK
open
Exploit-DBVexDay Proof
FastStone Image Viewer 2.9/3.6 - '.bmp' Image Handling Memory Corruption
CVE-2007-1942doswindows04 Apr 2007
Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possi
23RISK
open
Exploit-DBVexDay Proof
AOL SuperBuddy - ActiveX Control Remote Code Execution (Metasploit)
CVE-2006-5820remotewindows04 Apr 2007
The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition derefe
23RISK
open
Exploit-DBVexDay Proof
Gazi Okul Sitesi 2007 - 'Fotokategori.asp' SQL Injection
CVE-2007-1971webappsasp04 Apr 2007
SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
HP Mercury Quality Center 9.0 build 9.1.0.4352 - SQL Execution
CVE-2007-1882remotemultiple03 Apr 2007
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authen
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Overflow (Hardware DEP)
CVE-2007-1765localwindows03 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Universal Generator
CVE-2007-0038remotewindows03 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Universal Generator
CVE-2007-1765remotewindows03 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Overflow (Hardware DEP)
CVE-2007-0038localwindows03 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
Frontbase 4.2.7 - (Authenticated) Remote Buffer Overflow (2.2)
CVE-2007-1511remotewindows02 Apr 2007
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privil
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Buffer Overflow
CVE-2007-1765localwindows02 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
PulseAudio 0.9.5 - 'Assert()' Remote Denial of Service
CVE-2007-1804doslinux02 Apr 2007
PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LEN
23RISK
open
Exploit-DBVexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
CVE-2005-0725webappsphp02 Apr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISK
open
Exploit-DBVexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
CVE-2005-0725webappsphp02 Apr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISK
open
Exploit-DBVexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
CVE-2005-0725webappsphp02 Apr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Buffer Overflow
CVE-2007-0038localwindows02 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
WinMail Server 4.4 build 1124 - 'WebMail' Remote Add Super User
CVE-2005-3811webappsphp01 Apr 2007
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows rem
23RISK
open
Exploit-DBVexDay Proof
Symantec (Multiple Products) - 'SPBBCDrv' Driver Local Denial of Service
CVE-2007-1793doswindows01 Apr 2007
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before b
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP - Animated Cursor '.ani' Remote Overflow (2)
CVE-2007-0038remotewindows01 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
HP Instant Support - ActiveX Control Driver Check Buffer Overflow
CVE-2007-3554remotewindows01 Apr 2007
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check be
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/Vista - Animated Cursor '.ani' Remote Overflow
CVE-2007-0038remotewindows01 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Remote (eeye patch Bypass)
CVE-2007-0038remotewindows01 Apr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/Vista - Animated Cursor '.ani' Remote Overflow
CVE-2007-1765remotewindows01 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP - Animated Cursor '.ani' Remote Overflow (2)
CVE-2007-1765remotewindows01 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Remote (eeye patch Bypass)
CVE-2007-1765remotewindows01 Apr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISK
open
Exploit-DBVexDay Proof
IPSwitch IMail Server 8.20 - IMAPD Remote Buffer Overflow
CVE-2005-1255remotewindows01 Apr 2007
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), a
35RISK
open
previouspage 538 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.