Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
VCard Pro - 'gbrowse.php' Cross-Site Scripting
CVE-2007-0054webappsphp02 Jan 2007
Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'catalogue.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'shipping.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'search.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6 (PPC) - 'udp://' Format String (PoC)
CVE-2007-0017dososx02 Jan 2007
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA
28RISK
open
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6 (x86) - 'udp://' Format String
CVE-2007-0017localosx02 Jan 2007
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA
28RISK
open
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'basket.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 Jan 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RISK
open
Exploit-DBVexDay Proof
Georgia SoftWorks Secure Shell Server 7.1.3 - Multiple Remote Code Execution Vulnerabilities
CVE-2008-0096remotelinux02 Jan 2007
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Buffer Overflow (2)
CVE-2006-5551remotewindows01 Jan 2007
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RISK
open
Exploit-DBVexDay Proof
Kerio Personal Firewall 4.3 - 'IPHLPAPI.dll' Local Privilege Escalation
CVE-2007-0081localwindows01 Jan 2007
Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a
23RISK
open
Exploit-DBVexDay Proof
WWWBoard 2.0 - 'passwd.txt' Remote Password Disclosure
CVE-1999-0953webappscgi01 Jan 2007
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attacker
23RISK
open
Exploit-DBVexDay Proof
WinZip 10.0 - FileView ActiveX Controls Remote Overflow
CVE-2006-6884remotewindows31 Dec 2006
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZ
23RISK
open
Exploit-DBVexDay Proof
Rediff Bol Downloader - ActiveX Control Execute Local File
CVE-2006-6838remotewindows31 Dec 2006
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive inf
23RISK
open
Exploit-DBVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2007-0138doswindows31 Dec 2006
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - 'Csrss.exe/winsrv.dll' NtRaiseHardError Double-Free
CVE-2006-6797doswindows31 Dec 2006
The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash
23RISK
open
Exploit-DBVexDay Proof
x-news 1.1 - 'users.txt' Remote Password Disclosure
CVE-2002-1656webappsphp30 Dec 2006
X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the pas
23RISK
open
Exploit-DBVexDay Proof
Spooky 2.7 - 'login/register.asp' SQL Injection
CVE-2006-6861webappsasp30 Dec 2006
Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
Mobilelib Gold - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-6851webappsphp29 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
DMXReady Secure Login Manager 1.0 - 'login.asp?sent' SQL Injection
CVE-2006-6816webappsasp27 Dec 2006
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
DMXReady Secure Login Manager 1.0 - 'members.asp?sent' SQL Injection
CVE-2006-6816webappsasp27 Dec 2006
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'getdate' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'preferences.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'month.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
DMXReady Secure Login Manager 1.0 - 'content.asp?sent' SQL Injection
CVE-2006-6816webappsasp27 Dec 2006
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Hosting Controller 7C - 'FolderManager.aspx' Directory Traversal
CVE-2006-6814webappsasp27 Dec 2006
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticat
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'year.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
DMXReady Secure Login Manager 1.0 - '/applications/SecureLoginManager/inc_secureloginmanager.asp?sent' SQL Injection
CVE-2006-6816webappsasp27 Dec 2006
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'day.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'week.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 Dec 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RISK
open
Exploit-DBVexDay Proof
DB Hub 0.3 - Remote Denial of Service
CVE-2006-6810dosmultiple27 Dec 2006
Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a
23RISK
open
previouspage 555 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.