Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,401cataloged exploits
35,511CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Mozilla Firefox 2.0.0.2 - Document.Cookie Path Argument Denial of Service
CVE-2007-1362doslinux08 Mar 2007
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
FiSH-irssi - Multiple Remote Buffer Overflow Vulnerabilities
CVE-2007-1397doswindows08 Mar 2007
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote a
23RISK
open
Exploit-DBVexDay Proof
Adobe Reader Plugin 'AcroPDF.dll' 8.0.0.0 - Resource Consumption
CVE-2007-1377doswindows08 Mar 2007
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to caus
28RISK
open
Exploit-DBVexDay Proof
Rediff Toolbar - ActiveX Control Remote Denial of Service
CVE-2007-1402doswindows08 Mar 2007
The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via uns
23RISK
open
Exploit-DBVexDay Proof
mod_security 2.1.0 - ASCIIZ byte POST Rules Bypass
CVE-2007-1359remotemultiple07 Mar 2007
Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules
23RISK
open
Exploit-DBVexDay Proof
radscan conquest 8.2 - Multiple Vulnerabilities
CVE-2007-1371doslinux07 Mar 2007
Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver
23RISK
open
Exploit-DBVexDay Proof
Firebug 1.03 - Rep.JS Script Code Injection
CVE-2007-1947remotemultiple06 Mar 2007
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug exte
23RISK
open
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01b - 'check' Buffer Overflow (PoC)
CVE-2007-1373doswindows06 Mar 2007
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISK
open
Exploit-DBVexDay Proof
Silc Server 1.0.2 - New Channel Remote Denial of Service
CVE-2007-1327doslinux06 Mar 2007
The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
WinZip 10.0.7245 - FileView ActiveX Buffer Overflow (2)
CVE-2006-3890remotewindows06 Mar 2007
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in
28RISK
open
Exploit-DBVexDay Proof
EPortfolio 1.0 - Client-Side Input Validation
CVE-2007-1331webappsphp05 Mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
Gnome Evolution 2.x - GnuPG Arbitrary Content Injection
CVE-2007-1266remotelinux05 Mar 2007
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution
23RISK
open
Exploit-DBVexDay Proof
KMail 1.x - GnuPG Arbitrary Content Injection
CVE-2007-1264remotelinux05 Mar 2007
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail
23RISK
open
Exploit-DBVexDay Proof
GnuPG 1.x - Signed Message Arbitrary Content Injection
CVE-2007-1263remotelinux05 Mar 2007
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and
23RISK
open
Exploit-DBVexDay Proof
PHP 4.4.6 - 'mssql_[p]connect()' Local Buffer Overflow
CVE-2007-1411localwindows05 Mar 2007
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to
23RISK
open
Exploit-DBVexDay Proof
KDE Konqueror 3.5 - JavaScript IFrame Denial of Service
CVE-2007-1308doslinux05 Mar 2007
ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
KDE Konqueror 3.5.7 - Assert Denial of Service
CVE-2007-4229doslinux05 Mar 2007
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (faile
23RISK
open
Exploit-DBVexDay Proof
PHP 4.4.3 < 4.4.6 - 'PHPinfo()' Cross-Site Scripting
CVE-2007-1287remotemultiple04 Mar 2007
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct
23RISK
open
Exploit-DBVexDay Proof
Asterisk 1.2.15/1.4.0 - Remote Denial of Service
CVE-2007-1306dosmultiple04 Mar 2007
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending
28RISK
open
Exploit-DBVexDay Proof
RRDBrowse 1.6 - Arbitrary File Disclosure
CVE-2007-1303webappscgi04 Mar 2007
Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files
23RISK
open
Exploit-DBVexDay Proof
PHP < 4.4.5/5.2.1 - WDDX Session Deserialization Information Leak
CVE-2007-0908localmultiple04 Mar 2007
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize th
28RISK
open
Exploit-DBVexDay Proof
PHP 5 - 'wddx_deserialize()' String Append Crash
CVE-2007-1381dosmultiple04 Mar 2007
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and
23RISK
open
Exploit-DBVexDay Proof
Zend Platform 2.2.1 - 'PHP.INI' File Modification
CVE-2007-1369localphp03 Mar 2007
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by
23RISK
open
Exploit-DBVexDay Proof
PHP 4.4.4 - 'Unserialize()' ZVAL Reference Counter Overflow (PoC)
CVE-2007-1286doslinux02 Mar 2007
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISK
open
Exploit-DBVexDay Proof
Netrek 2.12.0 - 'pmessage2()' Remote Limited Format String
CVE-2007-1251doswindows02 Mar 2007
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENT
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.1.1 - '/wp-includes/theme.php?iz' Arbitrary Command Execution
CVE-2007-1277webappsphp02 Mar 2007
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.1.1 - Arbitrary Command Execution
CVE-2007-1277webappsphp02 Mar 2007
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RISK
open
Exploit-DBVexDay Proof
PHP 4 - Userland ZVAL Reference Counter Overflow (PoC)
CVE-2007-1383CRITICALdosmultiple01 Mar 2007
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitra
53RISK
open
Exploit-DBVexDay Proof
Built2go News Manager 1.0 Blog - 'rating.php?nid' Cross-Site Scripting
CVE-2007-1248webappsphp01 Mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISK
open
Exploit-DBVexDay Proof
Built2go News Manager 1.0 Blog - 'news.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-1248webappsphp01 Mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISK
open
previouspage 543 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.