Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
LoudBlog 0.41 - 'backend_settings.php' Traversal Arbitrary File Access
CVE-2006-1114webappsphp07 Mar 2006
Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary
23RISK
open
Exploit-DBVexDay Proof
LoudBlog 0.41 - 'index.php?template' Traversal Arbitrary File Access
CVE-2006-1114webappsphp07 Mar 2006
Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary
23RISK
open
Exploit-DBVexDay Proof
Limbo CMS 1.0.4.2 - 'itemID' Remote Code Execution (Metasploit)
CVE-2006-1662webappsphp07 Mar 2006
The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the
23RISK
open
Exploit-DBVexDay Proof
RevilloC MailServer 1.21 - 'USER' Remote Buffer Overflow
CVE-2006-1124remotewindows07 Mar 2006
Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER
23RISK
open
Exploit-DBVexDay Proof
Alien Arena 2006 Gold Edition 5.00 - Multiple Vulnerabilities
CVE-2006-1147doswindows07 Mar 2006
The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain lo
23RISK
open
Exploit-DBVexDay Proof
Link Bank - 'Iframe.php' Cross-Site Scripting
CVE-2006-1199webappsphp07 Mar 2006
Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
LoudBlog 0.41 - 'podcast.php' SQL Injection
CVE-2006-1113webappsphp07 Mar 2006
SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL comm
23RISK
open
Exploit-DBVexDay Proof
RunCMS 1.x - 'Bigshow.php' Cross-Site Scripting
CVE-2006-1216webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web sc
23RISK
open
Exploit-DBVexDay Proof
DVGuestbook 1.0/1.2.2 - 'dv_gbook.php?f' Cross-Site Scripting
CVE-2006-1070webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
PHORUM 3.x/5.x - 'Common.php' Remote File Inclusion
CVE-2006-3053webappsphp06 Mar 2006
PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Sauerbraten 2006_02_28 - Multiple Buffer Overflow / Crash
CVE-2006-1103doswindows06 Mar 2006
engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial
23RISK
open
Exploit-DBVexDay Proof
Cube 2005_08_29 - Multiple Buffer Overflow / Crash
CVE-2006-1101doswindows06 Mar 2006
The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Bitweaver 1.1/1.2 - 'Title' HTML Injection
CVE-2006-1131webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
HitHost 1.0 - 'deleteuser.php?user' Cross-Site Scripting
CVE-2006-1144webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Exploit-DBVexDay Proof
Freeciv 2.0.7 - Jumbo Malloc Crash (Denial of Service)
CVE-2006-0047doswindows06 Mar 2006
packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted pa
23RISK
open
Exploit-DBVexDay Proof
DVGuestbook 1.0/1.2.2 - 'index.php?page' Cross-Site Scripting
CVE-2006-1071webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary w
23RISK
open
Exploit-DBVexDay Proof
Invision Power Board 2.1.5 - showtopic SQL Injection
CVE-2006-1076webappsphp06 Mar 2006
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 all
23RISK
open
Exploit-DBVexDay Proof
Game-Panel 2.6 - 'login.php' Cross-Site Scripting
CVE-2006-1080webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Sauerbraten 2006_02_28 - Multiple Buffer Overflow / Crash
CVE-2006-1102doswindows06 Mar 2006
Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client ex
23RISK
open
Exploit-DBVexDay Proof
Monopd 0.9.3 - Remote Denial of Service
CVE-2006-1046dosmultiple06 Mar 2006
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a strin
23RISK
open
Exploit-DBVexDay Proof
MPCS 0.2 - 'comment.php' Cross-Site Scripting
CVE-2006-3191webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web scri
23RISK
open
Exploit-DBVexDay Proof
HitHost 1.0 - 'viewuser.php?hits' Cross-Site Scripting
CVE-2006-1144webappsphp06 Mar 2006
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML
23RISK
open
Exploit-DBVexDay Proof
Sauerbraten 2006_02_28 - Multiple Buffer Overflow / Crash
CVE-2006-1101doswindows06 Mar 2006
The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attack
23RISK
open
Exploit-DBVexDay Proof
Sauerbraten 2006_02_28 - Multiple Buffer Overflow / Crash
CVE-2006-1100doswindows06 Mar 2006
Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube
23RISK
open
Exploit-DBVexDay Proof
Microsoft Visual Studio 6.0 sp6 - '.dbp' Local Buffer Overflow
CVE-2006-1043localwindows05 Mar 2006
Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attack
28RISK
open
Exploit-DBVexDay Proof
LibTiff 3.7.1 - BitsPerSample Tag Local Buffer Overflow
CVE-2005-1544localmultiple05 Mar 2006
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file wi
28RISK
open
Exploit-DBVexDay Proof
TotalECommerce 1.0 - 'index.asp?id' SQL Injection
CVE-2006-1109webappsasp04 Mar 2006
SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DBVexDay Proof
VBZooM Forum 1.11 - 'comment.php?UserID' Cross-Site Scripting
CVE-2006-1133webappsphp04 Mar 2006
Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script
23RISK
open
Exploit-DBVexDay Proof
CutePHP CuteNews 1.4.1 - 'index.php' Cross-Site Scripting
CVE-2006-1121webappsphp04 Mar 2006
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTM
23RISK
open
Exploit-DBVexDay Proof
Easy Forum 2.5 - New User Image File HTML Injection
CVE-2006-0877webappsphp04 Mar 2006
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via
23RISK
open
previouspage 617 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.