Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

71,836cataloged exploits
32,133CVEs with public exploitation
1,932lab-tested
3,462 exploits
Metasploit300
MS06-055 Microsoft Internet Explorer VML Fill Method Code Execution
CVE-2006-486819 Sep 2006
Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet
50RISK
open
Metasploit200
Ipswitch WS_FTP Server 5.05 XMD5 Overflow
CVE-2006-484714 Sep 2006
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arb
60RISK
open
Metasploit600
TikiWiki jhot Remote Command Execution
CVE-2006-460202 Sep 2006
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execu
50RISK
open
Metasploit400
MaxDB WebDBM Database Parameter Overflow
CVE-2006-430529 Aug 2006
Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long databa
60RISK
open
Metasploit300
Cisco VPN Concentrator 3000 FTP Unauthorized Administrative Access
CVE-2006-431323 Aug 2006
Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x u
23RISK
open
Metasploit200
Texas Imperial Software WFTPD 3.23 SIZE Overflow
CVE-2006-431823 Aug 2006
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RISK
open
Metasploit400
MS06-040 Microsoft Server Service NetpwPathCanonicalize Overflow
CVE-2006-343908 Aug 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISK
open
Metasploit400
Apple iOS MobileSafari LibTIFF Buffer Overflow
CVE-2006-345901 Aug 2006
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Metasploit300
McAfee Subscription Manager Stack Buffer Overflow
CVE-2006-396101 Aug 2006
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite
50RISK
open
Metasploit400
Apple iOS MobileMail LibTIFF Buffer Overflow
CVE-2006-345901 Aug 2006
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RISK
open
Metasploit200
Easy File Sharing FTP Server 2.0 PASS Overflow
CVE-2006-395231 Jul 2006
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISK
open
Metasploit500
Apache Module mod_rewrite LDAP Protocol Buffer Overflow
CVE-2006-374728 Jul 2006
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RISK
open
Metasploit200
eIQNetworks ESA Topology DELETEDEVICE Overflow
CVE-2006-383825 Jul 2006
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open
Metasploit300
Mozilla Suite/Firefox Navigator Object Code Execution
CVE-2006-367725 Jul 2006
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by chang
60RISK
open
Metasploit200
eIQNetworks ESA License Manager LICMGR_ADDLICENSE Overflow
CVE-2006-383824 Jul 2006
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISK
open
Metasploit200
FileCopa FTP Server Pre 18 Jul Version
CVE-2006-372619 Jul 2006
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to
50RISK
open
Metasploit200
McAfee ePolicy Orchestrator / ProtectionPilot Overflow
CVE-2006-515617 Jul 2006
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RISK
open
Metasploit300
MS06-057 Microsoft Internet Explorer WebViewFolderIcon setSlice() Overflow
CVE-2006-3730HIGH17 Jul 2006
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RISK
open
Metasploit300
Microsoft SRV.SYS Mailslot Write Corruption
CVE-2006-394211 Jul 2006
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a de
60RISK
open
Metasploit500
SIPfoundry sipXezPhone 0.35a CSeq Field Overflow
CVE-2006-352410 Jul 2006
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open
Metasploit500
SIPfoundry sipXphone 2.6.0.27 CSeq Buffer Overflow
CVE-2006-352410 Jul 2006
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open
Metasploit500
AIM Triton 1.0.4 CSeq Buffer Overflow
CVE-2006-352410 Jul 2006
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RISK
open
Metasploit300
Webmin File Disclosure
CVE-2006-339230 Jun 2006
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RISK
open
Metasploit200
Private Wire Gateway Buffer Overflow
CVE-2006-325226 Jun 2006
Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows r
50RISK
open
Metasploit200
MS06-025 Microsoft RRAS Service Overflow
CVE-2006-237013 Jun 2006
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open
Metasploit400
MS06-025 Microsoft RRAS Service RASMAN Registry Overflow
CVE-2006-237013 Jun 2006
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RISK
open
Metasploit200
Cesar FTP 0.99g MKD Command Buffer Overflow
CVE-2006-296112 Jun 2006
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISK
open
Metasploit400
Qbik WinGate WWW Proxy Server URL Processing Overflow
CVE-2006-292607 Jun 2006
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISK
open
Metasploit600
SpamAssassin spamd Remote Command Execution
CVE-2006-244706 Jun 2006
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute a
60RISK
open
Metasploit400
Symantec Remote Management Buffer Overflow
CVE-2006-263024 May 2006
Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitr
60RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.