Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,383cataloged exploits
36,531CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
MDweb 1.3 - 'chemin_appli' Remote File Inclusion
CVE-2006-5587webappsphp
Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
ArticleBeach Script 2.0 - 'index.php' Remote File Inclusion
CVE-2006-5590webappsphp
PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
GestArt Beta 1 - 'aide.php?aide' Remote File Inclusion
CVE-2006-5612webappsphp
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled,
23RISK
open
ReferênciaVexDay Proof
mp3SDS 3.0 - '/Core/core.inc.php' Remote File Inclusion
CVE-2006-5613webappsphp
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabl
23RISK
open
ReferênciaVexDay Proof
Microsoft Windows - NAT Helper Components 'ipnathlp.dll' Remote Denial of Service
CVE-2006-5614doswindows
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISK
open
ReferênciaVexDay Proof
ask_rave 0.9 PR - 'end.php?footfile' Remote File Inclusion
CVE-2006-5621webappsphp
PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote att
23RISK
open
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.4.9 - SQL Injection
CVE-2006-5622webappsphp
SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Electronic Engineering Tool (EE TOOL) 0.4.1 - Remote File Inclusion
CVE-2006-5623webappsphp
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows
23RISK
open
ReferênciaVexDay Proof
N/X WCMS 4.1 - 'nxheader.inc.php' Remote File Inclusion
CVE-2006-5625webappsphp
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Manageme
23RISK
open
ReferênciaVexDay Proof
Article System 0.6 - 'volume.php' Remote File Inclusion
CVE-2006-5766webappsphp
PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
Drake CMS < 0.2.3 ALPHA rev.916 - Remote File Inclusion
CVE-2006-5767webappsphp
PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote
23RISK
open
ReferênciaVexDay Proof
phpDynaSite 3.2.2 - 'racine' Remote File Inclusion
CVE-2006-5760webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Free File Hosting 1.1 - 'forgot_pass.php' File Inclusion
CVE-2006-5762webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-5772webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
CVE-2006-5777webappsphp
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RISK
open
ReferênciaVexDay Proof
Omni-NFS Server 5.2 - 'nfsd.exe' Remote Stack Overflow (Metasploit)
CVE-2006-5780remotewindows
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-5773webappsphp
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RISK
open
ReferênciaVexDay Proof
SAP Web Application Server 6.40 - Arbitrary File Disclosure
CVE-2006-5784remotewindows
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 a
23RISK
open
ReferênciaVexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
CVE-2006-5787webappsphp
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RISK
open
ReferênciaVexDay Proof
Essentia Web Server 2.15 - GET Remote Denial of Service
CVE-2006-5850doswindows
Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code vi
23RISK
open
ReferênciaVexDay Proof
UPublisher 1.0 - 'viewarticle.asp' SQL Injection
CVE-2006-5888webappsasp
SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
Evince Document Viewer - 'DocumentMedia' Remote Buffer Overflow
CVE-2006-5864remotelinux
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows u
28RISK
open
ReferênciaVexDay Proof
PHPManta 1.0.2 - 'view-sourcecode.php' Local File Inclusion
CVE-2006-5866webappsphp
Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
NuRems 1.0 - 'propertysdetails.asp' SQL Injection
CVE-2006-5886webappsasp
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows rem
23RISK
open
ReferênciaVexDay Proof
BrewBlogger 1.3.1 - 'printLog.php' SQL Injection
CVE-2006-5889webappsphp
SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
AspPired2Poll 1.0 - 'MoreInfo.asp' SQL Injection
CVE-2006-5892webappsasp
SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
StoryStream 4.0 - 'baseDir' Remote File Inclusion
CVE-2006-5893webappsphp
Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
CVE-2006-6063localwindows
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RISK
open
ReferênciaVexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RISK
open
ReferênciaVexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
CVE-2006-6086webappsphp
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RISK
open
previouspage 182 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.