Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
AppServ Open Project 2.4.5 - Remote File Inclusion
CVE-2006-0125webappsphp09 Jan 2006
Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via th
23RISK
open
Exploit-DBVexDay Proof
Magic News Plus 1.0.3 - Admin Pass Change
CVE-2006-0157webappsphp09 Jan 2006
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password v
23RISK
open
Exploit-DBVexDay Proof
Venom Board - 'Post.php3' Multiple SQL Injections
CVE-2006-0160webappsphp09 Jan 2006
SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL comman
23RISK
open
Exploit-DBVexDay Proof
Microsoft Excel 95 < 2004 - Malformed Graphic File Code Execution
CVE-2006-0030doswindows09 Jan 2006
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allo
35RISK
open
Exploit-DBVexDay Proof
Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
CVE-2005-4158locallinux09 Jan 2006
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RISK
open
Exploit-DBVexDay Proof
PHP-Nuke News Submission Story - Text Field Cross-Site Scripting
CVE-2006-0185webappsphp09 Jan 2006
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows - Graphics Rendering Engine Multiple Memory Corruption Vulnerabilities
CVE-2006-0143doswindows09 Jan 2006
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of servic
35RISK
open
Exploit-DBVexDay Proof
PHP-Nuke 7.7 EV Search Module - SQL Injection
CVE-2006-0163webappsphp09 Jan 2006
SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
Dual DHCP DNS Server 1.0 - DHCP Options Remote Buffer Overflow
CVE-2006-0304dosmultiple07 Jan 2006
Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and
23RISK
open
Exploit-DBVexDay Proof
BlueCoat WinProxy 6.0 R1c - 'Host' Remote Stack Overflow (SEH)
CVE-2005-4085remotewindows07 Jan 2006
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.
50RISK
open
Exploit-DBVexDay Proof
BlueCoat WinProxy 6.0 R1c - GET Denial of Service
CVE-2005-3187doswindows07 Jan 2006
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
OnePlug CMS - '/products/details.asp?Product_ID' SQL Injection
CVE-2006-0115webappsasp06 Jan 2006
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
TinyPHPForum 3.6 - Multiple Directory Traversal Vulnerabilities
CVE-2006-0103webappsphp06 Jan 2006
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web roo
23RISK
open
Exploit-DBVexDay Proof
Foro Domus 2.10 - Multiple Input Validation Vulnerabilities
CVE-2006-0110webappsphp06 Jan 2006
Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
OnePlug CMS - '/press/details.asp?Press_Release_ID' SQL Injection
CVE-2006-0115webappsasp06 Jan 2006
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
OnePlug CMS - '/services/details.asp?Service_ID' SQL Injection
CVE-2006-0115webappsasp06 Jan 2006
Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL
23RISK
open
Exploit-DBVexDay Proof
TheWebForum 1.2.1 - Multiple Input Validation Vulnerabilities
CVE-2006-0135webappsphp06 Jan 2006
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL com
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 Kernel - APC Data-Free Local Escalation (MS05-055)
CVE-2005-2827localwindows05 Jan 2006
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify ker
23RISK
open
Exploit-DBVexDay Proof
PHP 4.4.0 - 'mysql_connect function' Local Buffer Overflow
CVE-2006-0097localwindows05 Jan 2006
Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Win
23RISK
open
Exploit-DBVexDay Proof
Hylafax 4.1/4.2 (Multiple Scripts) - Remote Command Execution
CVE-2005-3539remotelinux05 Jan 2006
Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary command
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - SET_MEMPOLICY Local Denial of Service
CVE-2005-3358doslinux04 Jan 2006
Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bit
23RISK
open
Exploit-DBVexDay Proof
WinRAR 3.30 - 'Filename' Local Buffer Overflow (1)
CVE-2005-4620localwindows04 Jan 2006
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument
23RISK
open
Exploit-DBVexDay Proof
WinRAR 3.30 - 'Filename' Local Buffer Overflow (2)
CVE-2005-4620localwindows04 Jan 2006
Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument
23RISK
open
Exploit-DBVexDay Proof
EFileGo 3.0 - Multiple Input Validation Vulnerabilities
CVE-2005-4622remotewindows03 Jan 2006
Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary file
23RISK
open
Exploit-DBVexDay Proof
SCO OpenServer 5.0.7 - 'termsh' Local Privilege Escalation
CVE-2006-0072localsco03 Jan 2006
Buffer overflow in termsh on SCO OpenServer 5.0.7 allows remote attackers to execute arbitrary code via a long -o comman
23RISK
open
Exploit-DBVexDay Proof
ScozNet ScozBook 1.1 - 'AdminName' SQL Injection
CVE-2006-0079webappsphp02 Jan 2006
SQL injection vulnerability in auth.php in ScozNet ScozBook BETA 1.1 allows remote attackers to execute arbitrary SQL co
23RISK
open
Exploit-DBVexDay Proof
DiscusWare Discus 3.10 - Error Message Cross-Site Scripting
CVE-2006-0073webappscgi02 Jan 2006
Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote atta
23RISK
open
Exploit-DBVexDay Proof
aMSN - Remote Denial of Service
CVE-2006-0138dosmultiple01 Jan 2006
aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of clien
23RISK
open
Exploit-DBVexDay Proof
IBM AIX 5.3 - 'GetShell' / 'GetCommand' File Disclosure
CVE-2006-0133localaix01 Jan 2006
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and r
23RISK
open
Exploit-DBVexDay Proof
Chimera Web Portal 0.2 - 'linkcategory.php?id' SQL Injection
CVE-2006-0137webappsphp01 Jan 2006
SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attack
23RISK
open
previouspage 628 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.