Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,385cataloged exploits
36,532CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Request For Travel 1.0 - 'product' SQL Injection
CVE-2006-6559webappsasp
SQL injection vulnerability in ProductDetails.asp in Lotfian Request For Travel 1.0 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' 'support' Local Buffer Overflow (1)
CVE-2006-6563locallinux
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RISK
open
ReferênciaVexDay Proof
Crob FTP Server 3.6.1 build 263 - 'LIST/NLST' Denial of Service
CVE-2006-6558doswindows
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in
23RISK
open
ReferênciaVexDay Proof
FileZilla FTP Server 0.9.21 - 'LIST/NLST' Denial of Service
CVE-2006-6565doswindows
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RISK
open
ReferênciaVexDay Proof
mxBB Module Profile CP 0.91c - Remote File Inclusion
CVE-2006-6566webappsphp
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module
23RISK
open
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6567webappsphp
PHP remote file inclusion vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB
23RISK
open
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6568webappsphp
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allow
23RISK
open
ReferênciaVexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
CVE-2006-6575webappsphp
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISK
open
ReferênciaVexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
CVE-2006-6586webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISK
open
ReferênciaVexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
CVE-2006-6612webappsphp
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISK
open
ReferênciaVexDay Proof
PHPAlbum 0.4.1 Beta 6 - 'language.php' Local File Inclusion
CVE-2006-6613webappsphp
Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disable
23RISK
open
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6604webappsphp
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISK
open
ReferênciaVexDay Proof
mxBB Module Activity Games 0.92 - Remote File Inclusion
CVE-2006-6615webappsphp
PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxB
23RISK
open
ReferênciaVexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISK
open
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RISK
open
ReferênciaVexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
CVE-2006-6686webappsphp
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
CVE-2006-6820webappsasp
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RISK
open
ReferênciaVexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RISK
open
ReferênciaVexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
CVE-2006-6823webappsphp
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
b2 Blog 0.5 - 'b2verifauth.php' Remote File Inclusion
CVE-2006-6830webappsphp
PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
aFAQ 1.0 - 'faqDsp.asp?catcode' SQL Injection
CVE-2006-6831webappsasp
SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RISK
open
ReferênciaVexDay Proof
phpBB2 Plus 1.53 - Acronym Mod SQL Injection
CVE-2006-6842webappsphp
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote atta
23RISK
open
ReferênciaVexDay Proof
wywo inout board 1.0 - Multiple Vulnerabilities
CVE-2006-6846webappsasp
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute ar
23RISK
open
ReferênciaVexDay Proof
RealPlayer 10.5 'ierpplug.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6847doswindows
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service
23RISK
open
ReferênciaVexDay Proof
ASPTicker 1.0 - Authentication Bypass
CVE-2006-6848webappsasp
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
CVE-2006-6850webappsphp
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RISK
open
ReferênciaVexDay Proof
AIDeX Mini-WebServer 1.1 - Remote Crash (Denial of Service)
CVE-2006-6855doswindows
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood
23RISK
open
ReferênciaVexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6863CRITICALwebappsphp
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RISK
open
ReferênciaVexDay Proof
SoftArtisans SAFileUp 5.0.14 - 'viewsrc.asp' Script Source Disclosure
CVE-2006-6865webappsasp
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows re
23RISK
open
ReferênciaVexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
CVE-2006-6871webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web scri
23RISK
open
previouspage 183 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.