Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5509webappsphp16 Oct 2006
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5508webappsphp16 Oct 2006
Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
KMail 1.x - HTML Element Handling Denial of Service
CVE-2006-7139doslinux16 Oct 2006
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
Comdev One Admin 4.1 - 'Adminfoot.php' Remote Code Execution
CVE-2006-6045webappsphp16 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitra
23RISK
open
Exploit-DBVexDay Proof
Nvidia Graphics Driver 8774 - Local Buffer Overflow
CVE-2006-5379locallinux16 Oct 2006
The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762,
28RISK
open
Exploit-DBVexDay Proof
Internet Security Systems 3.6 - 'ZWDeleteFile()' Arbitrary File Deletion
CVE-2006-7129localmultiple16 Oct 2006
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection s
23RISK
open
Exploit-DBVexDay Proof
Maintain 3.0.0-RC2 - 'Example6.php' Remote File Inclusion
CVE-2006-7120webappsphp16 Oct 2006
PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows
23RISK
open
Exploit-DBVexDay Proof
Microsoft Class Package Export Tool 5.0.2752 - 'Clspack.exe' Local Buffer Overflow (PoC)
CVE-2006-5395doswindows16 Oct 2006
Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
CampSite 2.6.1 - 'g_documentRoot' Remote File Inclusion
CVE-2006-5910webappsphp15 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execut
23RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - '/files/mainfile.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
FreeBSD 6.1-RELEASE-p10 - 'scheduler' Local Denial of Service
CVE-2006-5483dosbsd13 Oct 2006
p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, wh
23RISK
open
Exploit-DBVexDay Proof
FreeBSD 6.1-RELEASE-p10 - 'ftruncate' Local Denial of Service
CVE-2006-5482dosbsd13 Oct 2006
ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate functio
23RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'admin.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
phpBB Add Name Module - 'Not_Mem.php' Remote File Inclusion
CVE-2006-7168webappsphp13 Oct 2006
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
phpBB Amazonia Mod - 'zufallscodepart.php' Remote File Inclusion
CVE-2006-6593webappsphp13 Oct 2006
PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
Sun Solaris Netscape Portable Runtime API 4.6.1 - Local Privilege Escalation (1)
CVE-2006-4842localsolaris13 Oct 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISK
open
Exploit-DBVexDay Proof
Solaris 10 libnspr - 'LD_PRELOAD' Arbitrary File Creation Privilege Escalation (1)
CVE-2006-4842localsolaris13 Oct 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'index.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rdf.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rss.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rss2.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISK
open
Exploit-DBVexDay Proof
YaPiG 0.9x - 'Thanks_comment.php' Cross-Site Scripting
CVE-2006-4421webappsphp13 Oct 2006
Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG)
23RISK
open
Exploit-DBVexDay Proof
maluinfo 206.2.38 - 'bb_usage_stats.php' Remote File Inclusion
CVE-2006-7148webappsphp13 Oct 2006
PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows r
23RISK
open
Exploit-DBVexDay Proof
MamboLaiThai ExtCalThai 0.9.1 - 'admin_events.php?CONFIG_EXT[LANGUAGES_DIR]' Remote File Inclusion
CVE-2006-6634webappsphp12 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for M
23RISK
open
Exploit-DBVexDay Proof
MamboLaiThai ExtCalThai 0.9.1 - 'mail.inc.php?CONFIG_EXT[LIB_DIR]' Remote File Inclusion
CVE-2006-6634webappsphp12 Oct 2006
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for M
23RISK
open
Exploit-DBVexDay Proof
PHP TopSites FREE 1.022b - 'config.php' Remote File Inclusion
CVE-2006-7091webappsphp12 Oct 2006
PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
FreeBSD 5.4/6.0 - 'ptrace PT_LWPINFO' Local Denial of Service
CVE-2006-4516dosbsd12 Oct 2006
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and k
23RISK
open
Exploit-DBVexDay Proof
Download-Engine 1.4.2 - 'spaw' Remote File Inclusion
CVE-2006-4656webappsphp12 Oct 2006
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISK
open
Exploit-DBVexDay Proof
FreeWPS 2.11 - 'upload.php' Remote Command Execution
CVE-2006-5411webappsphp12 Oct 2006
Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier
23RISK
open
Exploit-DBVexDay Proof
phpList 2.x - Public Pages MultipleCross-Site Scripting Vulnerabilities
CVE-2006-5294webappsphp12 Oct 2006
Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitra
23RISK
open
previouspage 571 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.