Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
Oi! Email Marketing System 3.0 - 'index.php' SQL Injection
CVE-2006-0920webappsphp23 Feb 2006
Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, wh
23RISK
open
Exploit-DBVexDay Proof
NOCC 1.0 - 'html_bottom_table.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0894webappsphp23 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
CubeCart 3.0.x - Arbitrary File Upload
CVE-2006-0922webappsphp23 Feb 2006
CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.i
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6.1 Downloads Module - 'c' Cross-Site Scripting
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6.1 Stories_Archive Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Noah's Classifieds 1.0/1.3 - Local File Inclusion
CVE-2006-0882webappsphp22 Feb 2006
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary
23RISK
open
Exploit-DBVexDay Proof
Noah's Classifieds 1.0/1.3 - Search Page SQL Injection
CVE-2006-0879webappsphp22 Feb 2006
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
Noah's Classifieds 1.0/1.3 - 'index.php' Remote File Inclusion
CVE-2006-0881webappsphp22 Feb 2006
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals
23RISK
open
Exploit-DBVexDay Proof
RunCMS 1.x - 'Ratefile.php' Cross-Site Scripting
CVE-2006-0875webappsphp22 Feb 2006
Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web scrip
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6 1 News Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Ipswitch WhatsUp Professional 2006 - Remote Denial of Service
CVE-2006-0911dosasp22 Feb 2006
NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumptio
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Media Player - Plugin Overflow (MS06-006) (3)
CVE-2006-0005remotewindows22 Feb 2006
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Inter
35RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6 1 Your_Account Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
myPHPNuke 1.8.8 - 'download.php' Cross-Site Scripting
CVE-2006-0923webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6.1 Coppermine Module - 'album' Cross-Site Scripting
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6.1 Web_Links Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
Dragonfly CMS 9.0.6.1 Surveys Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-1033webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arb
23RISK
open
Exploit-DBVexDay Proof
myPHPNuke 1.8.8 - 'reviews.php' Cross-Site Scripting
CVE-2006-0923webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject
23RISK
open
Exploit-DBVexDay Proof
Mozilla (Multiple Products) - iFrame JavaScript Execution
CVE-2006-0884doslinux22 Feb 2006
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attacker
23RISK
open
Exploit-DBVexDay Proof
Noah's Classifieds 1.0/1.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0880webappsphp22 Feb 2006
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inj
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.6x/0.7x NS-Languages Module - 'language' Cross-Site Scripting
CVE-2006-0800webappsphp21 Feb 2006
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) atta
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.6x/0.7x NS-Languages Module - 'language' SQL Injection
CVE-2006-0801webappsphp21 Feb 2006
SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, all
23RISK
open
Exploit-DBVexDay Proof
CuteNews 1.4.1 - 'show_news.php' Cross-Site Scripting
CVE-2006-0885webappsphp20 Feb 2006
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
PunBB 2.0.10 - Register Multiple Users Denial of Service
CVE-2006-1090dosphp20 Feb 2006
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user r
23RISK
open
Exploit-DBVexDay Proof
TTS Software Time Tracking Software 3.0 - 'edituser.php' Access Validation
CVE-2006-0691webappsphp20 Feb 2006
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remo
23RISK
open
Exploit-DBVexDay Proof
PunBB 2.0.10 - Register Multiple Users Denial of Service
CVE-2006-0865dosphp20 Feb 2006
PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many
23RISK
open
Exploit-DBVexDay Proof
Magic Calendar Lite 1.02 - 'index.php' SQL Injection
CVE-2006-0673webappsphp20 Feb 2006
Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, all
23RISK
open
Exploit-DBVexDay Proof
MiniNuke 1.8.2b - 'pages.asp' SQL Injection
CVE-2006-0870webappsasp19 Feb 2006
SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.x - CAPTCHA Bypass
CVE-2006-0805webappsphp18 Feb 2006
The CAPTCHA functionality in php-Nuke 6.0 through 7.9 uses fixed challenge/response pairs that only vary once per day ba
23RISK
open
Exploit-DBVexDay Proof
Webpagecity WPC easy - SQL Injection
CVE-2006-0832webappsphp18 Feb 2006
Multiple SQL injection vulnerabilities in admin.asp in WPC.easy allow remote attackers to execute arbitrary SQL commands
23RISK
open
previouspage 620 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.