Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
DreamAccount 3.1 - 'auth.api.php' Remote File Inclusion
CVE-2006-6232webappsphp25 Jun 2006
PHP remote file inclusion vulnerability in admin/index.php in DreamAccount 3.1 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Winged Gallery 1.0 - 'Thumb.php' Cross-Site Scripting
CVE-2006-3563webappsphp24 Jun 2006
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject ar
23RISK
open
Exploit-DBVexDay Proof
MailEnable 1.x - SMTP 'HELO' Remote Denial of Service
CVE-2006-3277doswindows24 Jun 2006
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier b
23RISK
open
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.0.1 - 'Port' Remote Overflow (PoC)
CVE-2006-6750doswindows24 Jun 2006
Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (a
23RISK
open
Exploit-DBVexDay Proof
Jaws 0.6.2 - Search gadget SQL Injection
CVE-2006-3292webappsphp23 Jun 2006
SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands
23RISK
open
Exploit-DBVexDay Proof
Yahoo! Messenger 7.0/7.5 - 'jscript.dll' Non-ASCII Character Denial of Service
CVE-2006-3298doswindows23 Jun 2006
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that co
23RISK
open
Exploit-DBVexDay Proof
Usenet 0.5 - 'index.php' Cross-Site Scripting
CVE-2006-3299webappsphp23 Jun 2006
Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
BlueDragon Server 6.2.1 - '.cfm' Denial of Service
CVE-2006-2310doscfm23 Jun 2006
BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a
23RISK
open
Exploit-DBVexDay Proof
Mambo 4.6rc1 - Weblinks Blind SQL Injection (2)
CVE-2006-3262webappsphp22 Jun 2006
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
SoftBizScripts Dating Script 1.0 - 'featured_photos.php' SQL Injection
CVE-2006-3271webappsphp22 Jun 2006
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
ralf image Gallery 0.7.4 - Multiple Vulnerabilities
CVE-2007-4127webappsphp22 Jun 2006
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Galle
23RISK
open
Exploit-DBVexDay Proof
SoftBizScripts Dating Script 1.0 - 'news_desc.php' SQL Injection
CVE-2006-3271webappsphp22 Jun 2006
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
SoftBizScripts Dating Script 1.0 - 'index.php' SQL Injection
CVE-2006-3271webappsphp22 Jun 2006
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
Microsoft Office 2003 - Embedded Shockwave Flash Object Security Bypass
CVE-2006-3014doswindows22 Jun 2006
Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows RRAS - Remote Stack Overflow (MS06-025) (Metasploit)
CVE-2006-2370remotewindows22 Jun 2006
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open
Exploit-DBVexDay Proof
SoftBizScripts Dating Script 1.0 - 'products.php' SQL Injection
CVE-2006-3271webappsphp22 Jun 2006
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RISK
open
Exploit-DBVexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'report.php?postid' SQL Injection
CVE-2006-3256webappsphp22 Jun 2006
SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'newthread.php?boardid' SQL Injection
CVE-2006-3254webappsphp22 Jun 2006
SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
ralf image Gallery 0.7.4 - Multiple Vulnerabilities
CVE-2006-3210webappsphp22 Jun 2006
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers
28RISK
open
Exploit-DBVexDay Proof
PHP Event Calendar 4.2 - SQL Injection
CVE-2005-4011webappsphp22 Jun 2006
SQL injection vulnerability in calendar.php in Codewalkers ltwCalendar (aka PHP Event Calendar) 4.2, 4.1.3, and earlier
23RISK
open
Exploit-DBVexDay Proof
Microsoft Excel - Code Execution
CVE-2006-3059localwindows22 Jun 2006
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrar
35RISK
open
Exploit-DBVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Multiple Remote File Inclusions
CVE-2006-6958webappsphp22 Jun 2006
Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PH
23RISK
open
Exploit-DBVexDay Proof
Woltlab Burning Board 1.2/2.0/2.3 - 'showmods.php?boardid' SQL Injection
CVE-2006-3255webappsphp22 Jun 2006
SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitr
23RISK
open
Exploit-DBVexDay Proof
e107 0.7.5 - 'Subject' HTML Injection
CVE-2006-3259webappsphp21 Jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
Opera 9 - long href Remote Denial of Service
CVE-2006-3199dosmultiple21 Jun 2006
Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL cont
28RISK
open
Exploit-DBVexDay Proof
Maximus SchoolMAX 4.0.1 - 'Error_msg' Cross-Site Scripting
CVE-2006-3143webappsasp21 Jun 2006
Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent appli
23RISK
open
Exploit-DBVexDay Proof
vBulletin 3.0.9/3.5.x - 'member.php' Cross-Site Scripting
CVE-2006-3253webappsphp20 Jun 2006
Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
V3 Chat Instant Messenger - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3366webappsphp20 Jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open
Exploit-DBVexDay Proof
V3 Chat Instant Messenger - 'expire.php?cust_name' Cross-Site Scripting
CVE-2006-3366webappsphp20 Jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or
23RISK
open
Exploit-DBVexDay Proof
V3 Chat Instant Messenger - 'mycontacts.php' membername Arbitrary User Buddy List Manipulation
CVE-2006-6995webappsphp20 Jun 2006
mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername
23RISK
open
previouspage 593 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.