Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,647cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
21,899 exploits
ReferênciaVexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
CVE-2006-6216webappsphp
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RISK
open
ReferênciaVexDay Proof
Recipes Complete Website 1.1.14 - SQL Injection
CVE-2006-6220webappsphp
Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISK
open
ReferênciaVexDay Proof
S9Y Serendipity 1.0.3 - 'comment.php' Local File Inclusion
CVE-2006-6242webappsphp
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include
23RISK
open
ReferênciaVexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
CVE-2006-6250doswindows
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISK
open
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
CVE-2006-6251remotewindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISK
open
ReferênciaVexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISK
open
ReferênciaVexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
CVE-2006-6288localwindows
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISK
open
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
CVE-2006-6293doslinux
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RISK
open
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6568webappsphp
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allow
23RISK
open
Referência
CVE-2009-4721
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
CVE-2006-6575webappsphp
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISK
open
Referência
CVE-2006-6576
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RISK
open
ReferênciaVexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
CVE-2006-6586webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
AR Memberscript - 'usercp_menu.php' Remote File Inclusion
CVE-2006-6590webappsphp
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6604webappsphp
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISK
open
ReferênciaVexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
CVE-2006-6612webappsphp
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISK
open
Referência
CVE-2009-4725
Directory traversal vulnerability in modules/aljazeera/admin/setup.php in Arab Portal 2.2 and earlier, when register_glo
23RISK
open
ReferênciaVexDay Proof
mxBB Module Activity Games 0.92 - Remote File Inclusion
CVE-2006-6615webappsphp
PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxB
23RISK
open
ReferênciaVexDay Proof
Sambar FTP Server 6.4 - 'SIZE' Remote Denial of Service
CVE-2006-6624doswindows
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) v
23RISK
open
ReferênciaVexDay Proof
Genepi 1.6 - 'genepi.php' Remote File Inclusion
CVE-2006-6632webappsphp
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
JumbaCMS 0.0.1 - '/includes/functions.php' Remote File Inclusion
CVE-2006-6635webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
CVE-2006-6644webappsphp
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RISK
open
Referência
CVE-2015-7297
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RISK
open
Referência
CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Referência
CVE-2020-0688
CVE-2020-0688HIGHunder attackransomware
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RISK
open
Referência
CVE-2026-9627
UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
41RISK
open
Referência
CVE-2026-9583
SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
33RISK
open
Referência
CVE-2026-9582
SourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery
33RISK
open
Referência
CVE-2026-9582
SourceCodester CET Automated Grading System with AI Predictive Analytics cross-site request forgery
33RISK
open
previouspage 363 / 730next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.