Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
VihorDesign - 'index.php' Remote File Inclusion
CVE-2006-1497webappsphp24 Mar 2006
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the p
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.5.x/2.6.x - 'Sockaddr_In.Sin_Zero' Kernel Memory Disclosure
CVE-2006-1342locallinux23 Mar 2006
net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'createTextRang' Remote Code Execution
CVE-2006-1359remotewindows23 Mar 2006
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISK
open
Exploit-DBVexDay Proof
IBM Tivoli Business Systems Manager 3.1 - APWC_Win_Main.jsp Cross-Site Scripting
CVE-2006-1384webappsjsp23 Mar 2006
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager
23RISK
open
Exploit-DBVexDay Proof
EasyMoblog 0.5 - 'Img.php' Cross-Site Scripting
CVE-2006-1377webappsphp23 Mar 2006
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
CoMoblog 1.0 - 'Img.php' Cross-Site Scripting
CVE-2006-1377webappsphp23 Mar 2006
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
RealNetworks (Multiple Products) - Multiple Buffer Overflow Vulnerabilities
CVE-2006-0323dosmultiple23 Mar 2006
Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Playe
28RISK
open
Exploit-DBVexDay Proof
BomberClone < 0.11.6.2 - Error Messages Remote Buffer Overflow
CVE-2006-0460remotemultiple22 Mar 2006
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error
50RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2003 - IGMP v3 Denial of Service (MS06-007) (2)
CVE-2006-0021doswindows22 Mar 2006
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang)
35RISK
open
Exploit-DBVexDay Proof
1WebCalendar 4.0 - 'viewEvent.cfm?EventID' SQL Injection
CVE-2006-1372webappscfm22 Mar 2006
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
Motorola - BlueTooth Interface Dialog Spoofing
CVE-2006-1367webappsphp22 Mar 2006
The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones do
23RISK
open
Exploit-DBVexDay Proof
1WebCalendar 4.0 - 'mainCal.cfm' SQL Injection
CVE-2006-1372webappscfm22 Mar 2006
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
1WebCalendar 4.0 - '/news/newsView.cfm?NewsID' SQL Injection
CVE-2006-1372webappscfm22 Mar 2006
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
F5 Firepass 4100 SSL VPN - Cross-Site Scripting
CVE-2006-1357remotehardware21 Mar 2006
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to
23RISK
open
Exploit-DBVexDay Proof
LibVC - '.VCard' 003 Processing Buffer Overflow
CVE-2006-1356dosmultiple21 Mar 2006
Stack-based buffer overflow in the count_vcards function in LibVC 3, as used in Rolo, allows user-assisted attackers to
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.8.2/0.8.3 - 'article.php?sid' SQL Injection
CVE-2006-1330webappsphp20 Mar 2006
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
phpWebSite 0.8.2/0.8.3 - 'friend.php?sid' SQL Injection
CVE-2006-1330webappsphp20 Mar 2006
Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
Verisign MPKI 6.0 - 'Haydn.exe' Cross-Site Scripting
CVE-2006-1344webappscgi20 Mar 2006
Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attacke
23RISK
open
Exploit-DBVexDay Proof
X.Org X11 (X11R6.9.0/X11R7.0) - Local Privilege Escalation
CVE-2006-0745locallinux20 Mar 2006
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid funct
23RISK
open
Exploit-DBVexDay Proof
Mercur MailServer 5.0 SP3 - 'IMAP' Remote Buffer Overflow (1)
CVE-2006-1255remotewindows19 Mar 2006
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISK
open
Exploit-DBVexDay Proof
BetaParticle Blog 6.0 - 'fldGalleryID' SQL Injection
CVE-2006-1333webappsasp18 Mar 2006
Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Extcalendar 1.0 - Cross-Site Scripting
CVE-2006-1336webappsphp18 Mar 2006
Cross-site scripting vulnerability in calendar.php in ExtCalendar 1.0 and possibly other versions before 2.0 allows remo
23RISK
open
Exploit-DBVexDay Proof
MusicBox 2.3 - 'cart.php' Cross-Site Scripting
CVE-2006-1349webappsphp18 Mar 2006
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Woltlab Burning Board 2.3.4 - 'Class_DB_MySQL.php' Cross-Site Scripting
CVE-2006-1324webappsphp18 Mar 2006
Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remot
23RISK
open
Exploit-DBVexDay Proof
MusicBox 2.3 - 'index.php' SQL Injection
CVE-2005-4500webappsphp18 Mar 2006
SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show a
23RISK
open
Exploit-DBVexDay Proof
nodez 4.6.1.1 mercury - Multiple Vulnerabilities
CVE-2006-1164webappsphp18 Mar 2006
Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient acc
23RISK
open
Exploit-DBVexDay Proof
ShoutLIVE 1.1.0 - 'savesettings.php' Remote Code Execution
CVE-2006-0940webappsphp18 Mar 2006
Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
MusicBox 2.3 - 'index.php' Cross-Site Scripting
CVE-2006-1349webappsphp18 Mar 2006
Multiple cross-site scripting (XSS) vulnerabilities in Musicbox 2.3 Beta 2 allow remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
nodez 4.6.1.1 mercury - Multiple Vulnerabilities
CVE-2006-1162webappsphp18 Mar 2006
Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP
23RISK
open
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 2.0.4 - Mail Action 'MID' Cross-Site Scripting
CVE-2006-1326webappsphp17 Mar 2006
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbit
23RISK
open
previouspage 614 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.