Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,453cataloged exploits
35,554CVEs with public exploitation
24,695lab-tested
24,451 exploits
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'ISO9660' Denial of Service
CVE-2006-5757doslinux05 Nov 2006
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versio
23RISK
open
Exploit-DBVexDay Proof
IF-CMS - 'index.php' Cross-Site Scripting
CVE-2006-5761webappsphp04 Nov 2006
Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Sun Solaris 10 - 'UFS' Local Denial of Service
CVE-2006-5726dossolaris04 Nov 2006
alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mo
23RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - 'up.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
NullSoft Winamp 5.3 - Ultravox-Max-Msg Heap Overflow Denial of Service (PoC)
CVE-2006-5567doswindows03 Nov 2006
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute
28RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - 'MobileNews.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - '/cp/index.php?pagenav' Cross-Site Scripting
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - 'polls.php' Multiple Cross-Site Scripting Vulnerabilities (1)
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
ac4p Mobile - 'send.php?cats' Cross-Site Scripting
CVE-2006-5770webappsphp03 Nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - SquashFS Double-Free Denial of Service
CVE-2006-5701doslinux02 Nov 2006
Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other dist
23RISK
open
Exploit-DBVexDay Proof
Outpost Firewall PRO 4.0 - Local Denial of Service
CVE-2006-5721doswindows01 Nov 2006
The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (sy
23RISK
open
Exploit-DBVexDay Proof
TikiWiki 1.9.5 Sirius - 'sort_mode' Information Disclosure
CVE-2006-5703webappsphp01 Nov 2006
Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject a
23RISK
open
Exploit-DBVexDay Proof
2BGal 3.0 - '/admin/configuration.inc.php' Local File Inclusion
CVE-2006-5505webappsphp01 Nov 2006
Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the la
23RISK
open
Exploit-DBVexDay Proof
Apple Airport - 802.11 Probe Response Kernel Memory Corruption (PoC) (Metasploit)
CVE-2006-5710doshardware01 Nov 2006
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly
28RISK
open
Exploit-DBVexDay Proof
TikiWiki 1.9.5 Sirius - 'sort_mode' Information Disclosure
CVE-2006-5702webappsphp01 Nov 2006
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_m
50RISK
open
Exploit-DBVexDay Proof
Netquery 4.0 - 'NQUser.php' Cross-Site Scripting
CVE-2006-5661webappsphp31 Oct 2006
Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 1.5.0.7/2.0 - 'createRange' Remote Denial of Service
CVE-2006-5633dosmultiple31 Oct 2006
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a
23RISK
open
Exploit-DBVexDay Proof
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router - Information Disclosure
CVE-2006-5711remotehardware31 Oct 2006
ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP
23RISK
open
Exploit-DBVexDay Proof
Mirapoint Web Mail - 'Expression()' HTML Injection
CVE-2006-5712webappsphp31 Oct 2006
Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.x Journal Module - 'search.php' SQL Injection
CVE-2006-5720webappsphp31 Oct 2006
SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earl
23RISK
open
Exploit-DBVexDay Proof
iPlanet Messaging Server - Messenger Express Expression() HTML Injection
CVE-2006-5652webappsphp31 Oct 2006
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to in
23RISK
open
Exploit-DBVexDay Proof
Sun Java System 6.x - Messenger Express Cross-Site Scripting
CVE-2006-5653remotejava31 Oct 2006
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Expr
23RISK
open
Exploit-DBVexDay Proof
Evandor Easy notesManager 0.0.1 - 'login.php?Username' SQL Injection
CVE-2006-5662webappsasp30 Oct 2006
SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Exhibit Engine 1.22 - 'fstyles.php?toroot' Remote File Inclusion
CVE-2006-7184webappsphp30 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attac
23RISK
open
Exploit-DBVexDay Proof
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (2)
CVE-2006-5478remotenovell30 Oct 2006
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RISK
open
Exploit-DBVexDay Proof
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (3)
CVE-2006-5478remotenovell30 Oct 2006
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RISK
open
Exploit-DBVexDay Proof
Actionpoll 1.1.1 - '/db/PollDB.php?CONFIG_DATAREADERWRITER' Remote File Inclusion
CVE-2007-2065webappsphp30 Oct 2006
PHP remote file inclusion vulnerability in db/PollDB.php in Robert Ladstaetter ActionPoll 1.1.1 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NAT Helper Components Remote Denial of Service
CVE-2006-5614doswindows30 Oct 2006
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISK
open
Exploit-DBVexDay Proof
Foresite CMS - 'Index_2.php' Cross-Site Scripting
CVE-2006-5643webappsphp30 Oct 2006
Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary w
23RISK
open
previouspage 568 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.