Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Mambo Component Sitemap 2.0.0 - Remote File Inclusion
CVE-2006-3749webappsphp
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS,
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_hashcash 1.2.1 - Remote File Inclusion
CVE-2006-3750webappsphp
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows
23RISK
open
ReferênciaVexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
CVE-2006-3754webappsphp
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier a
23RISK
open
ReferênciaVexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
CVE-2006-3771webappsphp
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RISK
open
ReferênciaVexDay Proof
Mambo Component Mam-Moodle alpha - Remote File Inclusion
CVE-2006-3951webappsphp
PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote
23RISK
open
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 (French) - SFX Path Local Stack Overflow
CVE-2006-3912localwindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 - SFX Path Local Stack Overflow
CVE-2006-3912localwindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISK
open
ReferênciaVexDay Proof
PHP Forge 3 Beta 2 - 'cfg_racine' Remote File Inclusion
CVE-2006-3917webappsphp
PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
Portail PHP 1.7 - 'chemin' Remote File Inclusion
CVE-2006-3922webappsphp
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
WMNews 0.2a - 'base_datapath' Remote File Inclusion
CVE-2006-3928webappsphp
PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Mambo Component mambatStaff 3.1b - Remote File Inclusion
CVE-2006-3947webappsphp
PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlie
23RISK
open
ReferênciaVexDay Proof
MyNewsGroups 0.6b - 'myng_root' Remote Inclusion
CVE-2006-3966webappsphp
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsG
23RISK
open
ReferênciaVexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RISK
open
ReferênciaVexDay Proof
IRSR 0.2 - '_sysSessionPath' Remote File Inclusion
CVE-2006-4237webappsphp
PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and
23RISK
open
ReferênciaVexDay Proof
SportsPHool 1.0 - 'mainnav' Remote File Inclusion
CVE-2006-4278webappsphp
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
MVCnPHP 3.0 - glConf[path_libraries] Remote File Inclusion
CVE-2006-4160webappsphp
Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHPay 2.02 - 'nu_mail.inc.php?mail()' Remote Injection
CVE-2006-4210webappsphp
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to us
23RISK
open
ReferênciaVexDay Proof
LBlog 1.05 - 'comments.asp' SQL Injection
CVE-2006-4284webappsasp
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Fantastic News 2.1.3 - 'script_path' Remote File Inclusion
CVE-2006-4285webappsphp
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
NES Game and NES System c108122 - Remote File Inclusion
CVE-2006-4287webappsphp
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RISK
open
ReferênciaVexDay Proof
PHlyMail Lite 3.4.4 - 'mod.listmail.php' Remote File Inclusion
CVE-2006-4291webappsphp
PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.0
23RISK
open
ReferênciaVexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
CVE-2006-4656webappsphp
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISK
open
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2006-4669webappsphp
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
CVE-2006-4670webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
28RISK
open
ReferênciaVexDay Proof
SIPS 0.3.1 - 'box.inc.php' Remote File Inclusion
CVE-2006-4733webappsphp
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing syste
23RISK
open
ReferênciaVexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
CVE-2006-4671webappsphp
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RISK
open
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
CVE-2006-4714webappsphp
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RISK
open
ReferênciaVexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
CVE-2006-4716webappsphp
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
CVE-2006-4719webappsphp
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RISK
open
ReferênciaVexDay Proof
RaidenHTTPD 1.1.49 - 'SoftParserFileXml' Remote Code Execution
CVE-2006-4723remotewindows
PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_global
23RISK
open
previouspage 128 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.