Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,447cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
LoveCMS 1.4 - 'load' Traversal Arbitrary File Access
CVE-2007-1149webappsphp22 Feb 2007
Multiple directory traversal vulnerabilities in LoveCMS 1.4 allow remote attackers to read arbitrary files via a .. (dot
23RISK
open
Exploit-DBVexDay Proof
Oracle 10g - KUPW$WORKER.MAIN Grant/Revoke dba Permission
CVE-2006-3698remotemultiple22 Feb 2007
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln
23RISK
open
Exploit-DBVexDay Proof
Pyrophobia 2.1.3.1 - Traversal Arbitrary File Access
CVE-2007-1152webappsphp22 Feb 2007
Multiple directory traversal vulnerabilities in Pyrophobia 2.1.3.1 allow remote attackers to read arbitrary files via a
23RISK
open
Exploit-DBVexDay Proof
Pheap 1.x/2.0 - 'edit.php' Directory Traversal
CVE-2007-1140webappsphp22 Feb 2007
Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a
23RISK
open
Exploit-DBVexDay Proof
LoveCMS 1.4 - 'step' Remote File Inclusion
CVE-2007-1148webappsphp22 Feb 2007
PHP remote file inclusion vulnerability in install/index.php in LoveCMS 1.4 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2003 - ReadDirectoryChangesW Information Disclosure
CVE-2007-0843localwindows22 Feb 2007
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RISK
open
Exploit-DBVexDay Proof
Plantilla - 'list_main_pages.php?nfolder' Traversal Arbitrary File Access
CVE-2007-1138webappsphp22 Feb 2007
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attac
23RISK
open
Exploit-DBVexDay Proof
phpTrafficA 1.4.1 - 'plotStat.php?File' Traversal Local File Inclusion
CVE-2007-1076webappsphp21 Feb 2007
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to inclu
23RISK
open
Exploit-DBVexDay Proof
Magic News Plus 1.0.2 - 'preview.php?PHP_script_path' Remote File Inclusion
CVE-2007-1141webappsphp21 Feb 2007
PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Google Desktop - Cross-Site Scripting
CVE-2007-1085webappscgi21 Feb 2007
Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inje
28RISK
open
Exploit-DBVexDay Proof
Magic News Plus 1.0.2 - 'news.php?&link_parameters' Cross-Site Scripting
CVE-2007-1142webappsphp21 Feb 2007
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Magic News Plus 1.0.2 - 'n_layouts.php?link_parameters' Cross-Site Scripting
CVE-2007-1142webappsphp21 Feb 2007
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
phpTrafficA 1.4.1 - 'banref.php?lang' Traversal Local File Inclusion
CVE-2007-1076webappsphp21 Feb 2007
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to inclu
23RISK
open
Exploit-DBVexDay Proof
CedStat 1.31 - 'index.php' Cross-Site Scripting
CVE-2007-1020webappsphp21 Feb 2007
Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
AbleDesign MyCalendar 2.20.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-1050webappsphp20 Feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inje
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 8.0 Final - 'INSERT' SQL Injection
CVE-2007-1061webappsphp20 Feb 2007
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISK
open
Exploit-DBVexDay Proof
NukeSentinel 2.5.05 - 'nsbypass.php' Blind SQL Injection
CVE-2007-5125webappsphp20 Feb 2007
20RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 2.0.0.1 - 'location.hostname' Cross-Domain
CVE-2007-0981remotewindows20 Feb 2007
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remo
28RISK
open
Exploit-DBVexDay Proof
Design4Online - 'Userpages2 Page.asp' SQL Injection
CVE-2007-1077webappsasp20 Feb 2007
SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 8.0 Final - 'INSERT' Blind SQL Injection (MySQL)
CVE-2007-1061webappsphp20 Feb 2007
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - ImageIO GIF Image Integer Overflow
CVE-2007-1071dososx20 Feb 2007
Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a d
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Local File Access
CVE-2007-3406remotewindows20 Feb 2007
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attacke
28RISK
open
Exploit-DBVexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
CVE-2007-1493webappsphp20 Feb 2007
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, whic
23RISK
open
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'docs/examples/handlervalidate.spy?x' Cross-Site Scripting
CVE-2008-0980webappsphp19 Feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'spyce/examples/request.spy?name' Cross-Site Scripting
CVE-2008-0980webappsphp19 Feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Spyce 2.1.3 - 'spyce/examples/getpost.spy?Name' Cross-Site Scripting
CVE-2008-0980webappsphp19 Feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Spyce 2.1.3 - '/spyce/examples/formtag.spy' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0980webappsphp19 Feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 5.05 - XMD5 Remote Buffer Overflow (Metasploit)
CVE-2006-4847remotewindows19 Feb 2007
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arb
60RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' 'support' Local Buffer Overflow (2)
CVE-2006-6563locallinux19 Feb 2007
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RISK
open
Exploit-DBVexDay Proof
Apple iTunes 7.0.2 - XML Parsing Remote Denial of Service
CVE-2007-1008dososx19 Feb 2007
Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted
23RISK
open
previouspage 546 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.