Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
PHPManta 1.0.2 - 'view-sourcecode.php' Local File Inclusion
CVE-2006-5866webappsphp
Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
NuRems 1.0 - 'propertysdetails.asp' SQL Injection
CVE-2006-5886webappsasp
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows rem
23RISK
open
ReferênciaVexDay Proof
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
CVE-2006-5889webappsphp
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
CVE-2006-5892webappsasp
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
CVE-2006-5893webappsphp
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
FipsCMS 4.5 - 'index.asp' SQL Injection
CVE-2006-6115webappsasp
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL com
23RISK
open
ReferênciaVexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
CVE-2006-6116webappsasp
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
CVE-2006-6203webappsphp
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RISK
open
ReferênciaVexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
CVE-2006-6202webappsphp
PHP remote file inclusion vulnerability in modules/NukeAI/util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Pro
23RISK
open
ReferênciaVexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
CVE-2006-6250doswindows
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISK
open
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
CVE-2006-6251remotewindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open
ReferênciaVexDay Proof
AtomixMP3 < 2.3 - '.m3u' Local Buffer Overflow
CVE-2006-6287localwindows
Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pa
28RISK
open
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
CVE-2006-6352doslinux
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RISK
open
ReferênciaVexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
CVE-2006-6368webappsphp
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6380webappsasp
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
CVE-2006-6396localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
VMware 5.5.1 - 'ActiveX' Local Buffer Overflow
CVE-2006-6410localwindows
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb par
23RISK
open
ReferênciaVexDay Proof
J-OWAMP Web Interface 2.1b - 'link' Remote File Inclusion
CVE-2006-6453webappsphp
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated
23RISK
open
ReferênciaVexDay Proof
Request For Travel 1.0 - 'product' SQL Injection
CVE-2006-6559webappsasp
SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' 'support' Local Buffer Overflow (1)
CVE-2006-6563locallinux
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RISK
open
ReferênciaVexDay Proof
Crob FTP Server 3.6.1 build 263 - 'LIST/NLST' Denial of Service
CVE-2006-6558doswindows
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in
23RISK
open
ReferênciaVexDay Proof
FileZilla FTP Server 0.9.21 - 'LIST/NLST' Denial of Service
CVE-2006-6565doswindows
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RISK
open
ReferênciaVexDay Proof
mxBB Module Profile CP 0.91c - Remote File Inclusion
CVE-2006-6566webappsphp
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module
23RISK
open
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6567webappsphp
PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB
23RISK
open
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6568webappsphp
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allow
23RISK
open
ReferênciaVexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
CVE-2006-6575webappsphp
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISK
open
ReferênciaVexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
CVE-2006-6586webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
CVE-2006-6612webappsphp
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
PHPAlbum 0.4.1 Beta 6 - 'language.php' Local File Inclusion
CVE-2006-6613webappsphp
Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disable
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6604webappsphp
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISK
open
previouspage 183 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.