Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RISK
open
ReferênciaVexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
CVE-2006-2998webappsphp
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
Enthrallweb ePhotos 1.0 - 'subLevel2.asp' SQL Injection
CVE-2006-3027webappsasp
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
CVE-2006-3192webappsphp
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RISK
open
ReferênciaVexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
CVE-2006-3572webappsphp
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Winlpd 1.2 Build 1076 - Remote Buffer Overflow
CVE-2006-3670remotewindows
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a requ
23RISK
open
ReferênciaVexDay Proof
Mambo Component MoSpray 18RC1 - Remote File Inclusion
CVE-2006-3847webappsphp
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php
23RISK
open
ReferênciaVexDay Proof
X7 Chat 2.0.4 - 'old_prefix' Blind SQL Injection
CVE-2006-3851webappsphp
SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
CVE-2006-3995webappsphp
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RISK
open
ReferênciaVexDay Proof
Kayako eSupport 2.3.1 - 'subd' Remote File Inclusion
CVE-2006-4011webappsphp
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when regis
23RISK
open
ReferênciaVexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
CVE-2006-4042webappsphp
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
CVE-2006-4045webappsphp
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
CVE-2006-4046localwindows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RISK
open
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.WMF' CreateBrushIndirect Denial of Service
CVE-2006-4071doswindows
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP,
28RISK
open
ReferênciaVexDay Proof
IRSR 0.2 - '_sysSessionPath' Remote File Inclusion
CVE-2006-4237webappsphp
PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and
23RISK
open
ReferênciaVexDay Proof
SportsPHool 1.0 - 'mainnav' Remote File Inclusion
CVE-2006-4278webappsphp
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
MVCnPHP 3.0 - glConf[path_libraries] Remote File Inclusion
CVE-2006-4160webappsphp
Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
PHPay 2.02 - 'nu_mail.inc.php?mail()' Remote Injection
CVE-2006-4210webappsphp
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to us
23RISK
open
ReferênciaVexDay Proof
LBlog 1.05 - 'comments.asp' SQL Injection
CVE-2006-4284webappsasp
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Fantastic News 2.1.3 - 'script_path' Remote File Inclusion
CVE-2006-4285webappsphp
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
Mambo Component cropimage 1.0 - Remote File Inclusion
CVE-2006-4363webappsphp
PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo
23RISK
open
ReferênciaVexDay Proof
VistaBB 2.x - 'functions_mod_user.php' Remote File Inclusion
CVE-2006-4365webappsphp
Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
CVE-2006-4656webappsphp
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISK
open
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2006-4669webappsphp
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RISK
open
ReferênciaVexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
CVE-2006-4670webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
28RISK
open
ReferênciaVexDay Proof
SIPS 0.3.1 - 'box.inc.php' Remote File Inclusion
CVE-2006-4733webappsphp
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing syste
23RISK
open
ReferênciaVexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
CVE-2006-4671webappsphp
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RISK
open
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
CVE-2006-4714webappsphp
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RISK
open
ReferênciaVexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
CVE-2006-4716webappsphp
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RISK
open
previouspage 179 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.