Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
Referência
CVE-2016-20080
WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php
33RISK
open
Referência
CVE-2016-20078
WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php
33RISK
open
Referência
CVE-2016-20077
WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php
33RISK
open
Referência
CVE-2016-20076
WordPress Simple-Backup 2.7.11 Arbitrary File Deletion and Download
41RISK
open
Referência
CVE-2016-20075
WordPress Ultimate Product Catalog 3.8.6 Arbitrary File Upload RCE
41RISK
open
Referência
CVE-2016-20074
WordPress Lazy Content Slider Plugin 3.4 CSRF
33RISK
open
Referência
CVE-2016-20067
WordPress CP Polls 1.0.8 Cross-Site Request Forgery
33RISK
open
Referência
CVE-2026-34021
Lack of cryptographic protection in Wertheim SafeController 5400 enables RS-485 message sniffing and replay
41RISK
open
Referência
CVE-2026-12217
DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
41RISK
open
Referência
CVE-2026-12216
svaarala duktape duk_api_bytecode.c memory corruption
33RISK
open
Referência
CVE-2026-12204
ShopXO Scheduled Task Endpoint Crontab.php GoodsGiveIntegral authorization
33RISK
open
Referência
CVE-2026-12203
HKUDS AI-Trader Research Export agents.csv information disclosure
33RISK
open
ReferênciaVexDay Proof
FreeForum 0.9.7 - 'forum.php' Remote File Inclusion
CVE-2006-5230webappsphp
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISK
open
ReferênciaVexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Minichat 6.0 - 'ftag.php' Remote File Inclusion
CVE-2006-5283webappsphp
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP cod
23RISK
open
Referência
CVE-2009-4618
Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
PHP News Reader 2.6.4 - 'phpBB.inc.php' Remote File Inclusion
CVE-2006-5284webappsphp
PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and ear
23RISK
open
Referência
CVE-2009-4621
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
vTiger CRM 4.2 - 'calpath' Multiple Remote File Inclusions
CVE-2006-5289webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Download-Engine 1.4.2 - 'spaw' Remote File Inclusion
CVE-2006-5291webappsphp
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows re
23RISK
open
ReferênciaVexDay Proof
Exhibit Engine 1.5 RC 4 - 'photo_comment.php' File Inclusion
CVE-2006-5292webappsphp
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISK
open
ReferênciaVexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISK
open
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
Cdsagenda 4.2.9 - 'SendAlertEmail.php' File Inclusion
CVE-2006-5384webappsphp
PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 a
23RISK
open
ReferênciaVexDay Proof
phpBB SpamOborona Mod 1.0b - Remote File Inclusion
CVE-2006-5385webappsphp
PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows
23RISK
open
ReferênciaVexDay Proof
Specimen Image Database - 'client.php' Remote File Inclusion
CVE-2006-5419webappsphp
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when regis
23RISK
open
ReferênciaVexDay Proof
WSN Forum 1.3.4 - 'prestart.php' Remote Code Execution
CVE-2006-5421webappsphp
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoc
23RISK
open
previouspage 338 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.