Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
IDevSpot iSupport 1.8 - 'open_tickets.php?ticket_id' Cross-Site Scripting
CVE-2006-4884webappsphp12 Sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Telekorn Signkorn Guestbook 1.x - '/help/en/adminhelp3.php?dir_path' Remote File Inclusion
CVE-2006-4889webappsphp12 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_gl
28RISK
open
Exploit-DBVexDay Proof
Telekorn Signkorn Guestbook 1.x - '/help/en/adminhelp2.php?dir_path' Remote File Inclusion
CVE-2006-4889webappsphp12 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_gl
28RISK
open
Exploit-DBVexDay Proof
Telekorn Signkorn Guestbook 1.x - '/help/de/adminhelp1.php?dir_path' Remote File Inclusion
CVE-2006-4889webappsphp12 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_gl
28RISK
open
Exploit-DBVexDay Proof
Telekorn Signkorn Guestbook 1.x - '/help/de/adminhelp0.php?dir_path' Remote File Inclusion
CVE-2006-4889webappsphp12 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_gl
28RISK
open
Exploit-DBVexDay Proof
Telekorn Signkorn Guestbook 1.x - '/admin/preview.php?dir_path' Remote File Inclusion
CVE-2006-4889webappsphp12 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_gl
28RISK
open
Exploit-DBVexDay Proof
PHProg 1.0 - 'index.php?album' Cross-Site Scripting
CVE-2006-4754webappsphp11 Sep 2006
Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
PhpLinkExchange 1.0 - Include / Cross-Site Scripting
CVE-2006-4741webappsphp11 Sep 2006
PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
PHProg 1.0 - 'index.php?lang' Traversal Arbitrary File Access
CVE-2006-4753webappsphp11 Sep 2006
Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via
23RISK
open
Exploit-DBVexDay Proof
XHP CMS 0.5.1 - 'index.php' Cross-Site Scripting
CVE-2006-4751webappsphp11 Sep 2006
Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows rem
23RISK
open
Exploit-DBVexDay Proof
PhpLinkExchange 1.0 - Include / Cross-Site Scripting
CVE-2006-4742webappsphp11 Sep 2006
Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inje
23RISK
open
Exploit-DBVexDay Proof
Mercur MailServer 5.0 SP3 - 'IMAP' Remote Buffer Overflow (2)
CVE-2006-1255remotewindows11 Sep 2006
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open
Exploit-DBVexDay Proof
Open Bulletin Board 1.0.8 - 'ROOT_PATH' File Inclusion
CVE-2006-4722webappsphp10 Sep 2006
PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to exe
23RISK
open
Exploit-DBVexDay Proof
PHP 3 < 5 - Ini_Restore() 'Safe_mode' / 'open_basedir' Restriction Bypass
CVE-2006-4625localphp09 Sep 2006
PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, su
23RISK
open
Exploit-DBVexDay Proof
TextAds - 'delete.php?id' Cross-Site Scripting
CVE-2006-4747webappsphp09 Sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
TextAds - 'error.php?error' Cross-Site Scripting
CVE-2006-4747webappsphp09 Sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
Vikingboard 0.1b - 'report.php' Cross-Site Scripting
CVE-2006-4708webappsphp08 Sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
Sage 1.3.6 - Input Validation
CVE-2006-6919remotemultiple08 Sep 2006
Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context vi
23RISK
open
Exploit-DBVexDay Proof
X11R6 < 6.4 XKEYBOARD (sco x86) - Local Buffer Overflow
CVE-2006-4655localsco08 Sep 2006
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO
23RISK
open
Exploit-DBVexDay Proof
Vikingboard 0.1b - 'help.php' Cross-Site Scripting
CVE-2006-4708webappsphp08 Sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
X11R6 < 6.4 XKEYBOARD (Solaris/SPARC) - Local Buffer Overflow (1)
CVE-2006-4655localsolaris08 Sep 2006
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO
23RISK
open
Exploit-DBVexDay Proof
X11R6 < 6.4 XKEYBOARD (solaris x86) - Local Buffer Overflow
CVE-2006-4655localsolaris08 Sep 2006
Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO
23RISK
open
Exploit-DBVexDay Proof
Vikingboard 0.1 - 'topic.php' SQL Injection
CVE-2006-4709webappsphp08 Sep 2006
SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
PHP-Fusion 6.0.x - 'news.php' SQL Injection
CVE-2006-4673webappsphp07 Sep 2006
Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on th
23RISK
open
Exploit-DBVexDay Proof
ACGV News 0.9.1 - 'header.php' Remote File Inclusion
CVE-2006-4637webappsphp07 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
TWiki 4.0.x - 'Viewfile' Directory Traversal
CVE-2006-4294webappsphp07 Sep 2006
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary fil
23RISK
open
Exploit-DBVexDay Proof
AckerTodo 4.0 - 'index.php' Cross-Site Scripting
CVE-2006-4668webappsphp07 Sep 2006
Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
CVE-2006-5291webappsphp07 Sep 2006
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows re
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke Book Catalog Module 1.0 - 'upload.php' Arbitrary File Upload
CVE-2006-4666webappsphp07 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attack
23RISK
open
Exploit-DBVexDay Proof
News Evolution 3.0.3 - _NE[AbsPath] Remote File Inclusion
CVE-2006-4678webappsphp07 Sep 2006
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code vi
23RISK
open
previouspage 580 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.