Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Extcalendar 2.0 - 'Extcalendar.php' Remote File Inclusion
CVE-2006-3556webappsphp07 Jul 2006
PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Kaillera 0.86 - Message Buffer Overflow
CVE-2006-3491remotewindows06 Jul 2006
Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a
23RISK
open
Exploit-DBVexDay Proof
AdPlug 2.0 - Multiple Remote File Buffer Overflow Vulnerabilities
CVE-2006-3581remotelinux06 Jul 2006
Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execut
28RISK
open
Exploit-DBVexDay Proof
Microsoft Excel 2000-2004 - Style Handling and Repair Remote Code Execution
CVE-2006-3431remotewindows06 Jul 2006
Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arb
28RISK
open
Exploit-DBVexDay Proof
ATutor 1.5.x - '/admin/fix_content.php?submit' Cross-Site Scripting
CVE-2006-3484webappsphp06 Jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
ATutor 1.5.x - '/users/browse.php?cat' Cross-Site Scripting
CVE-2006-3484webappsphp06 Jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Hosting Controller 6.1 Hotfix 3.1 - Privilege Escalation
CVE-2006-3147webappsasp06 Jul 2006
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gai
23RISK
open
Exploit-DBVexDay Proof
ATutor 1.5.x - '/documentation/admin/index.php' Cross-Site Scripting
CVE-2006-3484webappsphp06 Jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Structured Graphics Control Denial of Service
CVE-2006-3427doswindows06 Jul 2006
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL at
28RISK
open
Exploit-DBVexDay Proof
ATutor 1.5.x - 'create_course.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3484webappsphp06 Jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
ATutor 1.5.x - 'password_reminder.php?forgot' Cross-Site Scripting
CVE-2006-3484webappsphp06 Jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 1.x/2.x - Multiple SQL Injections
CVE-2006-3543webappsphp05 Jul 2006
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbit
23RISK
open
Exploit-DBVexDay Proof
LifeType 1.0.5 - 'index.php?Date' SQL Injection
CVE-2006-3577webappsphp05 Jul 2006
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
Apple Safari Web Browser 2.0.4 - DHTML SetAttributeNode() Null Dereference Denial of Service
CVE-2006-3372dososx05 Jul 2006
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttribu
23RISK
open
Exploit-DBVexDay Proof
Randshop 0.9.3/1.2 - 'index.php' Remote File Inclusion
CVE-2006-3374webappsphp04 Jul 2006
PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Href Title Denial of Service
CVE-2006-3472doswindows04 Jul 2006
Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with a
28RISK
open
Exploit-DBVexDay Proof
ImgSvr 0.6.5 - POST Denial of Service
CVE-2006-3546doswindows04 Jul 2006
Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via
23RISK
open
Exploit-DBVexDay Proof
PHPWebGallery 1.x - 'comments.php' Cross-Site Scripting
CVE-2006-3476webappsphp04 Jul 2006
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'features.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
Glossaire 1.7 - Remote File Inclusion
CVE-2006-3363webappsphp03 Jul 2006
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to ex
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'delete.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'history.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'index.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - ADODB.Recordset Filter Property Denial of Service
CVE-2006-3354doswindows03 Jul 2006
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter propert
28RISK
open
Exploit-DBVexDay Proof
Gentoo-Specific MPG123 - URI Remote Buffer Overflow
CVE-2006-3355doslinux03 Jul 2006
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code vi
23RISK
open
Exploit-DBVexDay Proof
Plume CMS 1.0.4 - 'search.php?_PX_config[manager_path]' Remote File Inclusion
CVE-2006-3562webappsphp03 Jul 2006
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'contact.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'about.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
Exploit-DBVexDay Proof
VirtuaStore 2.0 - 'Password' SQL Injection
CVE-2006-3402webappsphp03 Jul 2006
SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the passwor
23RISK
open
Exploit-DBVexDay Proof
free QBoard 1.1 - 'faq.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 Jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RISK
open
previouspage 591 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.