Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'toprated.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
CVE-2006-4479webappsphp30 Aug 2006
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'shownews.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
Learn.com - 'Learncenter.asp' Cross-Site Scripting
CVE-2006-4540webappsphp30 Aug 2006
Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject a
23RISK
open
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-4543webappsphp30 Aug 2006
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
ModuleBased CMS - Multiple Remote File Inclusions
CVE-2006-4545webappsphp29 Aug 2006
PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (1)
CVE-2006-3124remotelinux29 Aug 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISK
open
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (2)
CVE-2006-3124remotewindows29 Aug 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISK
open
Exploit-DBVexDay Proof
HLstats 1.34 - 'hlstats.php' Cross-Site Scripting
CVE-2006-4454webappsphp29 Aug 2006
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Cybozu Products - 'id' Arbitrary File Retrieval
CVE-2006-4490webappscgi28 Aug 2006
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 al
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Daxctle.OCX Spline Method Heap Buffer Overflow
CVE-2006-4446remotewindows28 Aug 2006
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP
35RISK
open
Exploit-DBVexDay Proof
Cybuzu Garoon 2.1.0 - Multiple SQL Injections
CVE-2006-4444webappscgi28 Aug 2006
Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute ar
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - NetpIsRemote() Remote Overflow (MS06-040) (2)
CVE-2006-3439remotewindows28 Aug 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open
Exploit-DBVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4441webappsphp27 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (2)
CVE-2006-4927localwindows26 Aug 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISK
open
Exploit-DBVexDay Proof
Alt-N MDaemon POP3 Server < 9.06 - 'USER' Remote Heap Overflow
CVE-2006-4364remotewindows26 Aug 2006
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISK
open
Exploit-DBVexDay Proof
Jupiter CMS 1.1.5 - 'index.php' Remote File Inclusion
CVE-2006-4428CRITICALwebappsphp26 Aug 2006
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary P
48RISK
open
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - 'Search_function.php' Remote File Inclusion
CVE-2006-4422webappsphp26 Aug 2006
PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'download.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'admin.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (1)
CVE-2006-4927localwindows26 Aug 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISK
open
Exploit-DBVexDay Proof
MyBB 1.1.7 - Multiple HTML Injection Vulnerabilities
CVE-2006-4449webappsphp26 Aug 2006
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions a
23RISK
open
Exploit-DBVexDay Proof
Joomla! / Mambo Component Comprofiler 1.0 - 'class.php' Remote File Inclusion
CVE-2006-4553webappsphp26 Aug 2006
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joom
23RISK
open
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'item_main.php' Remote File Inclusion
CVE-2006-4423webappsphp26 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'upload_form.php' Remote File Inclusion
CVE-2006-4423webappsphp26 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
Alstrasoft Video Share Enterprise 4.x - 'MyajaxPHP.php' Remote File Inclusion
CVE-2006-4443webappsphp26 Aug 2006
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
BlackBoard Products 6 - Multiple HTML Injection Vulnerabilities
CVE-2006-4308webappsphp24 Aug 2006
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community P
23RISK
open
Exploit-DBVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4425webappsphp24 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code
23RISK
open
previouspage 582 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.