Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
CVE-2006-2888webappsphp
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
CVE-2006-2863webappsphp
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
CVE-2006-2929webappsphp
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earl
23RISK
open
ReferênciaVexDay Proof
blur6ex 0.3.462 - 'ID' Admin Disclosure / Blind SQL Injection
CVE-2006-3065webappsphp
SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
fipsGallery 1.5 - 'index1.asp' SQL Injection
CVE-2006-6117webappsasp
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6137webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP c
23RISK
open
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6138webappsphp
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary director
23RISK
open
ReferênciaVexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
CVE-2006-4158webappsphp
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Mambo Component Peoplebook 1.0 - Remote File Inclusion
CVE-2006-4195webappsphp
PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1
23RISK
open
ReferênciaVexDay Proof
Wheatblog 1.1 - 'session.php' Remote File Inclusion
CVE-2006-4198webappsphp
PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals
23RISK
open
ReferênciaVexDay Proof
Spidey Blog Script 1.5 - 'proje_goster.asp' SQL Injection (1)
CVE-2006-4202webappsasp
SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
WEBInsta MM 1.3e - 'cabsolute_path' Remote File Inclusion
CVE-2006-4209webappsphp
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
Thatware 0.4.6 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4213webappsphp
PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows re
23RISK
open
ReferênciaVexDay Proof
Wikepage Opus 10 < 2006.2a (lng) - Remote Command Execution
CVE-2006-4418webappsphp
Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary
23RISK
open
ReferênciaVexDay Proof
ProManager 0.73 - 'note.php' SQL Injection
CVE-2006-4419webappsphp
SQL injection vulnerability in note.php in ProManager 0.73 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
JiRos FAQ Manager 1.0 - 'index.asp' SQL Injection
CVE-2006-6149webappsphp
SQL injection vulnerability in index.asp in JiRos FAQ Manager 1.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection
CVE-2006-6160webappsasp
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
CVE-2006-4489webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
28RISK
open
ReferênciaVexDay Proof
C-News 1.0.1 - 'path' Remote File Inclusion
CVE-2006-4629webappsphp
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
MySpeach 3.0.2 - 'my_ms[root]' Remote File Inclusion
CVE-2006-4630webappsphp
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals
23RISK
open
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4633webappsphp
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISK
open
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
CVE-2006-6237webappsphp
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISK
open
ReferênciaVexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
CVE-2006-6295webappsphp
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - spoolss GetPrinterData() Remote Denial of Service
CVE-2006-6296doswindows
The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and
28RISK
open
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6328webappsphp
Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitr
23RISK
open
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6329webappsphp
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RISK
open
ReferênciaVexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
CVE-2008-0567webappsphp
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISK
open
ReferênciaVexDay Proof
Downstat 1.8 - 'art' Remote File Inclusion
CVE-2006-4827webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
CVE-2008-0572webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISK
open
previouspage 125 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.