Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,620cataloged exploits
35,647CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
ezb systems ultraiso 8.0.1392 - Directory Traversal
CVE-2006-2099remotewindows28 Apr 2006
Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - CIFS CHRoot Security Restriction Bypass
CVE-2006-1863locallinux28 Apr 2006
Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions f
23RISK
open
Exploit-DBVexDay Proof
DUclassified - 'detail.asp' SQL Injection
CVE-2006-2132webappsasp28 Apr 2006
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
Artmedic Event - 'index.php' Remote File Inclusion
CVE-2006-2119webappsphp28 Apr 2006
PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
winiso 5.3 - Directory Traversal
CVE-2006-2101remotewindows28 Apr 2006
Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a
23RISK
open
Exploit-DBVexDay Proof
BL4 SMTP Server < 0.1.5 - Remote Buffer Overflow (PoC)
CVE-2006-2107doswindows27 Apr 2006
Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or exe
23RISK
open
Exploit-DBVexDay Proof
Outlook Express 5.5/6.0 / Windows Mail - MHTML URI Handler Information Disclosure
CVE-2006-2111doswindows27 Apr 2006
A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive in
35RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Modal Dialog Manipulation
CVE-2006-2094remotewindows26 Apr 2006
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is conf
28RISK
open
Exploit-DBVexDay Proof
DevBB 1.0 - 'member.php' Cross-Site Scripting
CVE-2006-2070webappsphp26 Apr 2006
Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbi
23RISK
open
Exploit-DBVexDay Proof
Oracle 10g Release 2 - 'DBMS_EXPORT_EXTENSION' SQL
CVE-2006-2081localmultiple26 Apr 2006
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADA
43RISK
open
Exploit-DBVexDay Proof
Invision Power Board 2.1.5 - 'lastdate' Remote Code Execution
CVE-2006-2059webappsphp26 Apr 2006
action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execut
23RISK
open
Exploit-DBVexDay Proof
Oracle 10g Release 2 - 'DBMS_EXPORT_EXTENSION' SQL
CVE-2006-2505localmultiple26 Apr 2006
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious
23RISK
open
Exploit-DBVexDay Proof
CafeLog B2 0.6.1 Weblog and News Publishing Tool - 'b2archives.php?b2inc' Remote File Inclusion
CVE-2007-2290webappsphp25 Apr 2006
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
PhotoKorn 1.53/1.54 - 'print.php?cat' SQL Injection
CVE-2006-2040webappsphp25 Apr 2006
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
Instant Photo Gallery 1.0 - 'member.php?member' Cross-Site Scripting
CVE-2006-2052webappsphp25 Apr 2006
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitr
23RISK
open
Exploit-DBVexDay Proof
Instant Photo Gallery 1.0 - 'portfolio_photo_popup.php?id' Cross-Site Scripting
CVE-2006-2052webappsphp25 Apr 2006
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitr
23RISK
open
Exploit-DBVexDay Proof
Instant Photo Gallery 1.0 - 'portfolio.php?cat_id' Cross-Site Scripting
CVE-2006-2079webappsphp25 Apr 2006
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2,
23RISK
open
Exploit-DBVexDay Proof
PhotoKorn 1.53/1.54 - 'id' SQL Injection
CVE-2006-2040webappsphp25 Apr 2006
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
PhotoKorn 1.53/1.54 - 'index.php' Multiple SQL Injections
CVE-2006-2040webappsphp25 Apr 2006
Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL comma
23RISK
open
Exploit-DBVexDay Proof
CafeLog B2 0.6.1 Weblog and News Publishing Tool - 'b2mail.php?b2inc' Remote File Inclusion
CVE-2007-2290webappsphp25 Apr 2006
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Fenice Oms 1.10 - GET Remote Buffer Overflow
CVE-2006-2022remotelinux25 Apr 2006
Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote
28RISK
open
Exploit-DBVexDay Proof
CafeLog B2 0.6.1 Weblog and News Publishing Tool - 'b2categories.php?b2inc' Remote File Inclusion
CVE-2007-2290webappsphp25 Apr 2006
Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Cartweaver 2.16.11 - 'Results.cfm' SQL Injection
CVE-2006-2046webappscfm25 Apr 2006
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RISK
open
Exploit-DBVexDay Proof
NextAge Shopping Cart - Multiple HTML Injection Vulnerabilities
CVE-2006-2051webappsphp25 Apr 2006
Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
PHPWebFTP 2.3 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-2048webappsphp25 Apr 2006
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers
23RISK
open
Exploit-DBVexDay Proof
BK Forum 4.0 - 'member.asp' SQL Injection
CVE-2005-1287webappsasp24 Apr 2006
Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
Mozilla Firefox 1.5.0.2 - 'js320.dll/xpcom_core.dll' Denial of Service (PoC)
CVE-2006-1993dosmultiple24 Apr 2006
Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly e
35RISK
open
Exploit-DBVexDay Proof
Blender 2.36 - '.BVF' File Import Python Code Execution
CVE-2005-3302HIGHwebappscgi24 Apr 2006
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hi
41RISK
open
Exploit-DBVexDay Proof
Scry Gallery 1.1 - 'index.php' Cross-Site Scripting
CVE-2006-2001webappsphp24 Apr 2006
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
FlexBB 0.5.5 - '/function/showprofile.php' SQL Injection
CVE-2006-2034webappsphp24 Apr 2006
SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL
23RISK
open
previouspage 606 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.