Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,724cataloged exploits
35,724CVEs with public exploitation
24,695lab-tested
24,455 exploits
Exploit-DBVexDay Proof
InTouch 0.5.1 Alpha - User Variable SQL Injection
CVE-2006-0088webappsphp01 Jan 2006
SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL c
23RISK
open
Exploit-DBVexDay Proof
aMSN - Remote Denial of Service
CVE-2006-0138dosmultiple01 Jan 2006
aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of clien
23RISK
open
Exploit-DBVexDay Proof
PHPJournaler 1.0 - 'Readold' SQL Injection
CVE-2006-0066webappsphp01 Jan 2006
SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands v
23RISK
open
Exploit-DBVexDay Proof
Kayako SupportSuite 3.0 0.26 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4637webappsphp30 Dec 2005
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote
23RISK
open
Exploit-DBVexDay Proof
IBM AIX 5.3 - 'GetShell' / 'GetCommand' File Enumeration
CVE-2006-0133localaix30 Dec 2005
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and r
23RISK
open
Exploit-DBVexDay Proof
OOApp Guestbook 2.1 Home Script - Cross-Site Scripting
CVE-2005-4598webappsphp30 Dec 2005
Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary
23RISK
open
Exploit-DBVexDay Proof
Ades Design AdesGuestbook 2.0 Read Script - Cross-Site Scripting
CVE-2005-4596webappsphp30 Dec 2005
Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary we
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.9 < 2.6.11 (RHEL 4) - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation
CVE-2005-0736locallinux30 Dec 2005
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel
23RISK
open
Exploit-DBVexDay Proof
OABoard 1.0 Forum - Remote File Inclusion
CVE-2006-0076webappsphp29 Dec 2005
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - File Lock Lease Local Denial of Service
CVE-2005-3807doslinux29 Dec 2005
Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a de
23RISK
open
Exploit-DBVexDay Proof
GMailSite 1.0.x - Cross-Site Scripting
CVE-2005-4627webappsphp29 Dec 2005
Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.
23RISK
open
Exploit-DBVexDay Proof
PHPBook 1.x - Mail Field PHP Code Injection
CVE-2006-0075webappsphp29 Dec 2005
Direct static code injection vulnerability in phpBook 1.3.2 and earlier allows remote attackers to execute arbitrary PHP
23RISK
open
Exploit-DBVexDay Proof
phpDocumentor 1.3.0 rc4 - Remote Command Execution
CVE-2005-4593webappsphp29 Dec 2005
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows
28RISK
open
Exploit-DBVexDay Proof
Jevontech PHPenpals - PersonalID SQL Injection
CVE-2006-0074webappsphp29 Dec 2005
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via th
23RISK
open
Exploit-DBVexDay Proof
Phpclanwebsite 1.23.1 - BBCode IMG Tag Script Injection
CVE-2006-0366webappsphp28 Dec 2005
Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web scr
23RISK
open
Exploit-DBVexDay Proof
Dream4 Koobi 5.0 - BBCode URL Tag Script Injection
CVE-2005-4588webappsphp28 Dec 2005
Cross-site scripting (XSS) vulnerability in Koobi 5 allows remote attackers to inject arbitrary web script or HTML via n
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/dir/include.html?lang' Local File Inclusion
CVE-2005-4557webappsphp27 Dec 2005
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 b
23RISK
open
Exploit-DBVexDay Proof
Dev Web Management System 1.5 - 'download_now.php?target' SQL Injection
CVE-2005-4554webappsphp27 Dec 2005
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Dev Web Management System 1.5 - 'getfile.php?cat' SQL Injection
CVE-2005-4554webappsphp27 Dec 2005
Multiple SQL injection vulnerabilities in DEV web management system 1.5 and earlier allow remote attackers to execute ar
23RISK
open
Exploit-DBVexDay Proof
Dev Web Management System 1.5 - 'add.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4555webappsphp27 Dec 2005
Cross-site scripting (XSS) vulnerability in add.php in DEV web management system 1.5 and earlier allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/mail/include.html' Crafted HTTP_USER_AGENT Arbitrary File Access
CVE-2005-4559webappsphp27 Dec 2005
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/admin/inc/include.php' Multiple Remote File Inclusions
CVE-2005-4556webappsphp27 Dec 2005
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail S
28RISK
open
Exploit-DBVexDay Proof
Cerberus Helpdesk 2.649 - 'addresses_export.php?queues' SQL Injection
CVE-2005-4427webappsphp27 Dec 2005
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/mail/settings.html?Language' Local File Inclusion
CVE-2005-4558webappsphp27 Dec 2005
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not pro
23RISK
open
Exploit-DBVexDay Proof
FatWire UpdateEngine 6.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4576webappsjava27 Dec 2005
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/mail/index.html?lang_settings' Remote File Inclusion
CVE-2005-4558webappsphp27 Dec 2005
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not pro
23RISK
open
Exploit-DBVexDay Proof
Cerberus Helpdesk 2.649 - 'cer_KnowledgebaseHandler.class.php?_load_article_details' SQL Injection
CVE-2005-4427webappsphp27 Dec 2005
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
Cerberus Helpdesk 2.649 - 'display_ticket_thread.php?ticket' SQL Injection
CVE-2005-4427webappsphp27 Dec 2005
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via
23RISK
open
Exploit-DBVexDay Proof
BZFlag 2.0.4 - undelimited string Denial of Service
CVE-2005-4584dosmultiple27 Dec 2005
BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign
23RISK
open
Exploit-DBVexDay Proof
IceWarp Universal WebMail - '/accounts/inc/include.php' Multiple Remote File Inclusions
CVE-2005-4556webappsphp27 Dec 2005
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail S
28RISK
open
previouspage 629 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.