Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4368webappsphp
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RISK
open
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4369webappsphp
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RISK
open
ReferênciaVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4440webappsphp
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
PHPECard 2.1.4 - 'functions.php' Remote File Inclusion
CVE-2006-4456webappsphp
PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Nokia Symbian 60 3rd Edition - Browser Crash (Denial of Service)
CVE-2006-4464doshardware
The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (
23RISK
open
ReferênciaVexDay Proof
Pheap CMS 1.1 - 'lpref' Remote File Inclusion
CVE-2006-4531webappsphp
PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
CMS Frogss 0.4 - 'podpis' SQL Injection
CVE-2006-4536webappsphp
SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Lanifex DMO 2.3b - '_incMgr' Remote File Inclusion
CVE-2006-4604webappsphp
PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Be
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4605webappsphp
PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Multiple SQL Injections
CVE-2006-4606webappsphp
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4606webappsphp
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4607webappsphp
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting
23RISK
open
ReferênciaVexDay Proof
ACGV News 0.9.1 - 'article.php' Remote File Inclusion
CVE-2006-4638webappsphp
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Muratsoft Haber Portal 3.6 - 'tr' SQL Injection
CVE-2006-4641webappsasp
SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary S
23RISK
open
ReferênciaVexDay Proof
Akarru 0.4.3.34 - 'bm_content' Remote File Inclusion
CVE-2006-4645webappsphp
PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and
23RISK
open
ReferênciaVexDay Proof
SIPS 0.3.1 - 'box.inc.php' Remote File Inclusion
CVE-2006-4733webappsphp
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing syste
23RISK
open
ReferênciaVexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
CVE-2006-4671webappsphp
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RISK
open
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
CVE-2006-4714webappsphp
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RISK
open
ReferênciaVexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
CVE-2006-4716webappsphp
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
CVE-2006-4719webappsphp
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RISK
open
ReferênciaVexDay Proof
RaidenHTTPD 1.1.49 - 'SoftParserFileXml' Remote Code Execution
CVE-2006-4723remotewindows
PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_global
23RISK
open
ReferênciaVexDay Proof
Web Server Creator 0.1 - 'l' Remote File Inclusion
CVE-2006-4746webappsphp
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers
23RISK
open
ReferênciaVexDay Proof
MobilePublisherPHP 1.5 RC2 - Remote File Inclusion
CVE-2006-4849webappsphp
PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
BolinOS 4.5.5 - 'gBRootPath' Remote File Inclusion
CVE-2006-4850webappsphp
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
Q-Shop 3.5 - 'browse.asp' SQL Injection
CVE-2006-4852webappsasp
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_serverstat 0.4.4 - Remote File Inclusion
CVE-2006-4858webappsphp
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier c
23RISK
open
ReferênciaVexDay Proof
Techno Dreams FAQ Manager 1.0 - SQL Injection
CVE-2006-4892webappsasp
SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
CMtextS 1.0 - '/users_logins/admin.txt' Credentials Disclosure
CVE-2006-4897webappsphp
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, whic
23RISK
open
ReferênciaVexDay Proof
guanxiCRM Business Solution 0.9.1 - Remote File Inclusion
CVE-2006-4898webappsphp
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attacker
23RISK
open
ReferênciaVexDay Proof
more.groupware 0.74 - 'new_calendarid' SQL Injection
CVE-2006-4906webappsphp
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbit
23RISK
open
previouspage 180 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.