Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHP Krazy Image Hosting 0.7a - 'display.php' SQL Injection
CVE-2006-5140webappsphp
SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote at
23RISK
open
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'Content-Type' Stack Overflow Crash
CVE-2006-5162doswindows
wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unh
35RISK
open
ReferênciaVexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
CVE-2006-5165webappsphp
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RISK
open
ReferênciaVexDay Proof
BasiliX 1.1.1 - 'BSX_LIBDIR' Remote File Inclusion
CVE-2006-5167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-5180webappsphp
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISK
open
ReferênciaVexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISK
open
ReferênciaVexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISK
open
ReferênciaVexDay Proof
phpBB lat2cyr Mod 1.0.1 - 'lat2cyr.php' Remote File Inclusion
CVE-2006-5305webappsphp
PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attac
23RISK
open
ReferênciaVexDay Proof
Open Conference Systems 1.1.4 - 'fullpath' File Inclusion
CVE-2006-5308webappsphp
Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
TribunaLibre 3.12 Beta - 'ftag.php' Remote File Inclusion
CVE-2006-5314webappsphp
PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5315webappsphp
PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code
23RISK
open
ReferênciaVexDay Proof
eboli - 'index.php' Remote File Inclusion
CVE-2006-5317webappsphp
PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via
23RISK
open
ReferênciaVexDay Proof
Album Photo Sans Nom 1.6 - Remote Source Disclosure
CVE-2006-5320webappsphp
Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary fi
23RISK
open
ReferênciaVexDay Proof
phpBB PlusXL 2.0_272 - 'constants.php' Remote File Inclusion
CVE-2006-5387webappsphp
PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module
23RISK
open
ReferênciaVexDay Proof
PHPht Topsites - 'common.php' Remote File Inclusion
CVE-2006-5458webappsphp
PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Open Meetings Filing Application - Remote File Inclusion
CVE-2006-5517webappsphp
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote
23RISK
open
ReferênciaVexDay Proof
EZ-Ticket 0.0.1 - 'common.php' Remote File Inclusion
CVE-2006-5523webappsphp
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke 7.9 - 'Encyclopedia' SQL Injection
CVE-2006-5525webappsphp
Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL in
23RISK
open
ReferênciaVexDay Proof
Fully Modded phpBB 2021.4.40 - Multiple File Inclusions
CVE-2006-5526webappsphp
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 202
23RISK
open
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5548webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0
23RISK
open
ReferênciaVexDay Proof
RevilloC MailServer 1.x - 'RCPT TO' Remote Denial of Service
CVE-2006-5552doswindows
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of
23RISK
open
ReferênciaVexDay Proof
Imageview 5 - '/Cookie/index.php' Local/Remote File Inclusion
CVE-2006-5554webappsphp
Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local
23RISK
open
ReferênciaVexDay Proof
HP-UX 11i - 'swask' Format String Privilege Escalation
CVE-2006-5558localhp-ux
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to exec
23RISK
open
ReferênciaVexDay Proof
SourceForge 1.0.4 - 'database.php' Remote File Inclusion
CVE-2006-5562webappsphp
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote atta
23RISK
open
ReferênciaVexDay Proof
MDweb 1.3 - 'chemin_appli' Remote File Inclusion
CVE-2006-5587webappsphp
Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
ArticleBeach Script 2.0 - 'index.php' Remote File Inclusion
CVE-2006-5590webappsphp
PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
GestArt Beta 1 - 'aide.php?aide' Remote File Inclusion
CVE-2006-5612webappsphp
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
mp3SDS 3.0 - '/Core/core.inc.php' Remote File Inclusion
CVE-2006-5613webappsphp
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabl
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - NAT Helper Components 'ipnathlp.dll' Remote Denial of Service
CVE-2006-5614doswindows
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISK
open
previouspage 182 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.