Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
TFTPD32 2.81 - GET Format String Denial of Service (PoC)
CVE-2006-0328doswindows19 Jan 2006
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string speci
23RISK
open
Exploit-DBVexDay Proof
WebspotBlogging 3.0 - 'login.php' SQL Injection
CVE-2006-0324webappsphp19 Jan 2006
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass
23RISK
open
Exploit-DBVexDay Proof
EggBlog 2.0 - 'message' Cross-Site Scripting
CVE-2006-0350webappsphp18 Jan 2006
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML vi
23RISK
open
Exploit-DBVexDay Proof
SaralBlog 1.0 - Multiple Input Validation Vulnerabilities
CVE-2006-0345webappsphp18 Jan 2006
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the
23RISK
open
Exploit-DBVexDay Proof
EggBlog 2.0 - 'id' SQL Injection
CVE-2006-0349webappsphp18 Jan 2006
SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id paramete
23RISK
open
Exploit-DBVexDay Proof
MySQL 4.x - CREATE Temporary TABLE Symlink Privilege Escalation
CVE-2005-0711remotemultiple18 Jan 2006
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allo
23RISK
open
Exploit-DBVexDay Proof
Computer Associates Unicenter 6.0 - Remote Control DM Primer Remote Denial of Service
CVE-2006-0306doswindows17 Jan 2006
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup
28RISK
open
Exploit-DBVexDay Proof
aoblogger 2.3 - URL BBcode Cross-Site Scripting
CVE-2006-0310webappsphp17 Jan 2006
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a j
23RISK
open
Exploit-DBVexDay Proof
microBlog 2.0 - 'index.php' Multiple SQL Injections
CVE-2006-0234webappsphp17 Jan 2006
SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL command
23RISK
open
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - 'index.php' Cross-Site Scripting
CVE-2006-0358webappsphp17 Jan 2006
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - 'search.php' Cross-Site Scripting
CVE-2006-0358webappsphp17 Jan 2006
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute
23RISK
open
Exploit-DBVexDay Proof
aoblogger 2.3 - 'create.php' Entry Creation
CVE-2006-0312webappsphp17 Jan 2006
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the
23RISK
open
Exploit-DBVexDay Proof
aoblogger 2.3 - 'login.php?Username' SQL Injection
CVE-2006-0311webappsphp17 Jan 2006
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
pcAnywhere 8.0/9.0/11.x - Authentication Denial of Service
CVE-2005-3934doswindows17 Jan 2006
Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a
23RISK
open
Exploit-DBVexDay Proof
Cerberus FTP Server 2.32 - Denial of Service
CVE-2006-0357doswindows16 Jan 2006
Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified d
23RISK
open
Exploit-DBVexDay Proof
SimpleBlog 2.1 - Multiple Input Validation Vulnerabilities
CVE-2006-0240webappsasp16 Jan 2006
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RISK
open
Exploit-DBVexDay Proof
Veritas NetBackup 4/5 - Volume Manager Daemon Remote Buffer Overflow
CVE-2005-3116remotewindows16 Jan 2006
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterpri
28RISK
open
Exploit-DBVexDay Proof
White Album 2.5 - 'Pictures.php' SQL Injection
CVE-2006-0235webappsphp16 Jan 2006
SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir para
23RISK
open
Exploit-DBVexDay Proof
Apache Tomcat / Geronimo 1.0 - 'Sample Script cal2.jsp?time' Cross-Site Scripting
CVE-2006-0254remotemultiple16 Jan 2006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary we
35RISK
open
Exploit-DBVexDay Proof
BlogPHP 1.0 - 'index.php' SQL Injection
CVE-2006-0318webappsphp16 Jan 2006
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to e
23RISK
open
Exploit-DBVexDay Proof
Apache Geronimo 1.0 - Error Page Cross-Site Scripting
CVE-2006-0254remotemultiple16 Jan 2006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary we
35RISK
open
Exploit-DBVexDay Proof
PHPXplorer 0.9.33 - 'Workspaces.php' Directory Traversal
CVE-2006-0244webappsphp16 Jan 2006
Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary fi
23RISK
open
Exploit-DBVexDay Proof
Bit 5 Blog 8.1 - 'index.php' SQL Injection
CVE-2006-0320webappsphp16 Jan 2006
SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQ
23RISK
open
Exploit-DBVexDay Proof
GTP iCommerce - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0237webappsphp16 Jan 2006
Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web s
23RISK
open
Exploit-DBVexDay Proof
RedKernel Referrer Tracker 1.1.0-3 - 'Rkrt_stats.php' Cross-Site Scripting
CVE-2006-0317webappsphp16 Jan 2006
Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
EZDatabase 2.1.1 - 'index.php' Cross-Site Scripting
CVE-2006-0315webappsphp16 Jan 2006
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php
23RISK
open
Exploit-DBVexDay Proof
Ultimate Auction 3.67 - ItemList.pl Cross-Site Scripting
CVE-2006-0217webappscgi16 Jan 2006
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Faq-O-Matic 2.711 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0251webappscgi16 Jan 2006
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web
23RISK
open
Exploit-DBVexDay Proof
Bit 5 Blog 8.1 - 'addcomment.php' HTML Injection
CVE-2006-0361webappsphp16 Jan 2006
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrar
23RISK
open
Exploit-DBVexDay Proof
CounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (2)
CVE-2006-0359doswindows15 Jan 2006
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device cr
23RISK
open
previouspage 626 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.