Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,533cataloged exploits
35,607CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4425webappsphp24 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
RedBlog 0.5 - 'index.php' Remote File Inclusion
CVE-2006-4366webappsphp22 Aug 2006
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP cod
23RISK
open
Exploit-DBVexDay Proof
Solaris 10 sysinfo(2) - Local Kernel Memory Disclosure (2)
CVE-2006-3824localsolaris22 Aug 2006
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo sys
23RISK
open
Exploit-DBVexDay Proof
Solaris 8/9 - '/usr/ucb/ps' Local Information Leak
CVE-1999-1587localsolaris22 Aug 2006
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environmen
23RISK
open
Exploit-DBVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2009-3962doshardware22 Aug 2006
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.
23RISK
open
Exploit-DBVexDay Proof
cPanel 10.x - 'dohtaccess.html?dir' Cross-Site Scripting
CVE-2006-4293webappsphp21 Aug 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
Easy File Sharing FTP Server 2.0 - 'PASS' Remote
CVE-2006-3952remotewindows21 Aug 2006
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open
Exploit-DBVexDay Proof
DieselScripts Smart Traffic - 'index.php' Remote File Inclusion
CVE-2006-4357webappsphp21 Aug 2006
PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Multiple COM Object Color Property Denial of Service Vulnerabilities
CVE-2006-4301doswindows21 Aug 2006
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Multiple COM Object Instantiation Code Execution Vulnerabilities
CVE-2006-4495doswindows21 Aug 2006
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execut
28RISK
open
Exploit-DBVexDay Proof
DieselScripts DieselPay - 'index.php' Cross-Site Scripting
CVE-2006-4358webappsphp21 Aug 2006
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
cPanel 10.x - 'editit.html?File' Cross-Site Scripting
CVE-2006-4293webappsphp21 Aug 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
cPanel 10.x - 'showfile.html?File' Cross-Site Scripting
CVE-2006-4293webappsphp21 Aug 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RISK
open
Exploit-DBVexDay Proof
PHProjekt Content Management Module 0.6.1 - Multiple Remote File Inclusions
CVE-2006-4609webappsphp21 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.
23RISK
open
Exploit-DBVexDay Proof
ToendaCMS 0.x/1.0.x - 'TCMS_Administer' Remote File Inclusion
CVE-2006-4349webappsphp21 Aug 2006
PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP
23RISK
open
Exploit-DBVexDay Proof
Mambo Component EstateAgent 1.0.2 - MosConfig_absolute_path Remote File Inclusion
CVE-2006-4322webappsphp21 Aug 2006
PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, whe
23RISK
open
Exploit-DBVexDay Proof
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow
CVE-2006-3747remotemultiple21 Aug 2006
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open
Exploit-DBVexDay Proof
DieselScripts Diesel Paid Mail - 'Getad.php' Cross-Site Scripting
CVE-2006-4362webappsphp21 Aug 2006
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
XennoBB 1.0.x/2.2 - Icon_Topic SQL Injection
CVE-2006-4279webappsphp19 Aug 2006
SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - CanonicalizePathName() Remote (MS06-040)
CVE-2006-3439remotewindows19 Aug 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open
Exploit-DBVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4277webappsphp19 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
Novell Identity Manager - Arbitrary Command Execution
CVE-2006-4310localnovell18 Aug 2006
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when at
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Artlinks 1.0b4 - Remote File Inclusion
CVE-2006-3949webappsphp18 Aug 2006
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allow
23RISK
open
Exploit-DBVexDay Proof
Sonium Enterprise Adressbook 0.2 - 'folder' Include
CVE-2006-4311webappsphp18 Aug 2006
PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Joomla! Component Mosets Tree 1.0 - Remote File Inclusion
CVE-2006-3990webappsphp17 Aug 2006
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree compo
28RISK
open
Exploit-DBVexDay Proof
MySQL 4/5 - SUID Routine Miscalculation Arbitrary DML Statement Execution
CVE-2006-4227remotelinux17 Aug 2006
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's
28RISK
open
Exploit-DBVexDay Proof
CubeCart 3.0.11 - 'oid' Blind SQL Injection
CVE-2006-4267webappsphp17 Aug 2006
Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
GNU BinUtils 2.1x - GAS Buffer Overflow
CVE-2005-4807remotelinux17 Aug 2006
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundati
28RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - 'TSUserEX.dll' ActiveX Control Memory Corruption
CVE-2006-4219remotewindows17 Aug 2006
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibl
28RISK
open
Exploit-DBVexDay Proof
PHP 4.4.3/5.1.4 - 'sscanf' Local Buffer Overflow
CVE-2006-4020locallinux16 Aug 2006
scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code vi
23RISK
open
previouspage 583 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.