Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,107cataloged exploits
36,322CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Q-Shop 3.5 - 'browse.asp' SQL Injection
CVE-2006-4852webappsasp
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
Mambo Component com_serverstat 0.4.4 - Remote File Inclusion
CVE-2006-4858webappsphp
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier c
23RISK
open
ReferênciaVexDay Proof
Pie Cart Pro - 'Home_Path' Remote File Inclusion
CVE-2006-4970webappsphp
PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4978webappsphp
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arb
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - Remote Code Execution
CVE-2006-4962webappsphp
Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read
23RISK
open
ReferênciaVexDay Proof
phpQuestionnaire 3.12 - 'phpQRootDir' Remote File Inclusion
CVE-2006-4966webappsphp
PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote at
23RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
CVE-2006-4968webappsphp
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
faceStones personal 2.0.42 - 'fs_form_links.php' File Inclusion
CVE-2006-5070webappsphp
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allo
23RISK
open
ReferênciaVexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
CVE-2006-5078webappsphp
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RISK
open
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
CVE-2006-5079webappsphp
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
evoBB 0.3 - 'path' Remote File Inclusion
CVE-2006-5087webappsphp
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
A-Blog 2.0 - 'menu.php' Remote File Inclusion
CVE-2006-5092webappsphp
PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
TagIt! Tagboard 2.1.b b2 - 'index.php' Remote File Inclusion
CVE-2006-5093webappsphp
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows re
23RISK
open
ReferênciaVexDay Proof
Dimension of phpBB 0.2.6 - 'phpbb_root_path' Remote File Inclusions
CVE-2006-5222webappsphp
Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
FreeForum 0.9.7 - 'forum.php' Remote File Inclusion
CVE-2006-5230webappsphp
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Ciamos CMS 0.9.6b - 'config.php' Remote File Inclusion
CVE-2006-5257webappsphp
PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.
23RISK
open
ReferênciaVexDay Proof
compteur 2.0 - 'param_editor.php' Remote File Inclusion
CVE-2006-5259webappsphp
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary P
23RISK
open
ReferênciaVexDay Proof
PHPMyNews 1.4 - 'cfg_include_dir' Remote File Inclusion
CVE-2006-5261webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RISK
open
ReferênciaVexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISK
open
ReferênciaVexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RISK
open
ReferênciaVexDay Proof
PHP News Reader 2.6.4 - 'phpBB.inc.php' Remote File Inclusion
CVE-2006-5284webappsphp
PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and ear
23RISK
open
ReferênciaVexDay Proof
vTiger CRM 4.2 - 'calpath' Multiple Remote File Inclusions
CVE-2006-5289webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISK
open
ReferênciaVexDay Proof
phpBB lat2cyr Mod 1.0.1 - 'lat2cyr.php' Remote File Inclusion
CVE-2006-5305webappsphp
PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attac
23RISK
open
ReferênciaVexDay Proof
Open Conference Systems 1.1.4 - 'fullpath' File Inclusion
CVE-2006-5308webappsphp
Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers
23RISK
open
ReferênciaVexDay Proof
TribunaLibre 3.12 Beta - 'ftag.php' Remote File Inclusion
CVE-2006-5314webappsphp
PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5315webappsphp
PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code
23RISK
open
previouspage 103 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.