Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
HP (Multiple Products) - PML Driver HPZ12 Privilege Escalation
CVE-2007-0161localwindows08 Jan 2007
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE
23RISK
open
Exploit-DBVexDay Proof
Application Enhancer (APE) 2.0.2 - Local Privilege Escalation
CVE-2007-0162localosx08 Jan 2007
Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and
23RISK
open
Exploit-DBVexDay Proof
OpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege Escalation
CVE-2007-0085localbsd07 Jan 2007
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when th
23RISK
open
Exploit-DBVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow (Metasploit)
CVE-2006-5112remotewindows07 Jan 2007
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISK
open
Exploit-DBVexDay Proof
Easy Banner Pro 2.8 - 'info.php' Remote File Inclusion
CVE-2007-0178webappsphp07 Jan 2007
PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
WordPress Core 2.0.5 - Trackback UTF-7 SQL Injection
CVE-2007-0107webappsphp07 Jan 2007
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,
23RISK
open
Exploit-DBVexDay Proof
Shopstorenow E-Commerce Shopping Cart - 'Orange.asp' SQL Injection
CVE-2007-0142webappsasp06 Jan 2007
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Multiple PDF Readers - Multiple Remote Buffer Overflows
CVE-2007-0103doslinux06 Jan 2007
The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknow
28RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag_mp.cgi?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 Jan 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw.pl?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw.cgi?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag_mp.pl?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 Jan 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.10 - 'xpl.php' SQL Injection
CVE-2007-3558webappsphp05 Jan 2007
SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM Privilege Escalation
CVE-2007-0117localosx05 Jan 2007
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RISK
open
Exploit-DBVexDay Proof
Adobe Acrobat Reader Plugin 7.0.x - 'acroreader' Cross-Site Scripting
CVE-2007-0046remotewindows05 Jan 2007
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows re
35RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag.pl?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 Jan 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open
Exploit-DBVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0133webappsphp05 Jan 2007
Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag.cgi?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 Jan 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RISK
open
Exploit-DBVexDay Proof
Symantec Backup Exec System Recovery Manager 7.0 - FileUpload Class Unauthorized File Upload
CVE-2008-0457remotewindows05 Jan 2007
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISK
open
Exploit-DBVexDay Proof
Kolayindir Download - 'down.asp' SQL Injection
CVE-2007-0140webappsasp05 Jan 2007
SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
RI Blog 1.3 - 'search.asp' Cross-Site Scripting
CVE-2007-0121webappsphp05 Jan 2007
Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.11 - SQL Injection
CVE-2007-0122webappsphp05 Jan 2007
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RISK
open
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw_mp.cgi?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM 'cron' Local Privilege Escalation
CVE-2007-0117localosx05 Jan 2007
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RISK
open
Exploit-DBVexDay Proof
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
CVE-2007-0015remotewindows03 Jan 2007
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RISK
open
Exploit-DBVexDay Proof
Apple QuickTime 7.1.3 - 'HREFTrack' Cross-Zone Scripting
CVE-2007-0059remoteosx03 Jan 2007
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Adobe Reader 9.1.3 Plugin - Cross-Site Scripting
CVE-2007-0044remotelinux03 Jan 2007
Adobe Acrobat Reader Plugin before 8.0.0 for the Firefox, Internet Explorer, and Opera web browsers allows remote attack
35RISK
open
Exploit-DBVexDay Proof
MyServer 0.9.8 - Post.MSCGI Cross-Site Scripting
CVE-2007-3364remotemultiple02 Jan 2007
Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Georgia SoftWorks Secure Shell Server 7.1.3 - Multiple Remote Code Execution Vulnerabilities
CVE-2008-0096remotelinux02 Jan 2007
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'basket.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open
previouspage 554 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.