Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,559cataloged exploits
34,978CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
ProgSys 0.156 - 'RR.php' Remote File Inclusion
CVE-2006-4944webappsphp
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attac
23RISK
open
ReferênciaVexDay Proof
Digital WebShop 1.128 - Multiple Remote File Inclusions
CVE-2006-4945webappsphp
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al
23RISK
open
Referência
CVE-2009-4596
Cross-site scripting (XSS) vulnerability in index.php in PHP Inventory 1.2 allows remote attackers to inject arbitrary w
23RISK
open
ReferênciaVexDay Proof
MyReview 1.9.4 - 'email' SQL Injection / Code Execution
CVE-2006-4957webappsphp
SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to exec
23RISK
open
Referência
CVE-2009-4597
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4961webappsphp
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dr
23RISK
open
Referência
CVE-2009-4597
Multiple SQL injection vulnerabilities in index.php in PHP Inventory 1.2 allow (1) remote authenticated users to execute
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
ZoomStats 1.0.2 - 'mysql.php' Remote File Inclusion
CVE-2006-5065webappsphp
PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is
23RISK
open
Referência
CVE-2009-4598
SQL injection vulnerability in the JPhoto (com_jphoto) component 1.0 for Joomla! allows remote attackers to execute arbi
23RISK
open
ReferênciaVexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISK
open
ReferênciaVexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
CVE-2006-5665webappsphp
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RISK
open
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISK
open
ReferênciaVexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
CVE-2006-5673webappsphp
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RISK
open
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RISK
open
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5725remotewindows
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RISK
open
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
CVE-2006-5728doswindows
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-5773webappsphp
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
CVE-2006-5777webappsphp
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RISK
open
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
CVE-2006-5787webappsphp
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RISK
open
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Remote File Inclusion
CVE-2006-5788webappsphp
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RISK
open
ReferênciaVexDay Proof
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
CVE-2006-5795webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow
23RISK
open
ReferênciaVexDay Proof
PHPAdventure 1.1 - 'ad_main.php' Remote File Inclusion
CVE-2006-5839webappsphp
PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RISK
open
ReferênciaVexDay Proof
Essentia Web Server 2.15 - GET Remote Denial of Service
CVE-2006-5850doswindows
Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
CVE-2006-5851localosx
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RISK
open
previouspage 342 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.