Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,386cataloged exploits
36,533CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Pagetool CMS 1.07 - 'pt_upload.php' Remote File Inclusion
CVE-2006-6765webappsphp
Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Jinzora 2.7 - 'INCLUDE_PATH' Multiple Remote File Inclusions
CVE-2006-6770webappsphp
Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is en
23RISK
open
ReferênciaVexDay Proof
Irokez Blog 0.7.1 - Multiple Remote File Inclusions
CVE-2006-6771webappsphp
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RISK
open
ReferênciaVexDay Proof
Ciberia Content Federator 1.0.1 - 'path' Remote File Inclusion
CVE-2006-6774webappsphp
PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Cont
23RISK
open
ReferênciaVexDay Proof
acFTP FTP Server 1.5 - 'REST/PBSZ' Remote Denial of Service
CVE-2006-6775doswindows
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) P
23RISK
open
ReferênciaVexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
CVE-2006-6785webappsphp
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication
23RISK
open
ReferênciaVexDay Proof
Calendar MX BASIC 1.0.2 - 'ID' SQL Injection
CVE-2006-6792webappsasp
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
myPHPNuke Module My_eGallery 2.5.6 - 'basepath' Remote File Inclusion
CVE-2006-6795webappsphp
PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN
23RISK
open
ReferênciaVexDay Proof
MTCMS 2.0 - '/admin/admin_settings.php' Remote File Inclusion
CVE-2006-6796webappsphp
PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to
23RISK
open
ReferênciaVexDay Proof
SH-News 0.93 - 'misc.php' Remote File Inclusion
CVE-2006-6801webappsphp
PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote att
23RISK
open
ReferênciaVexDay Proof
Enthrallweb ePages - 'actualpic.asp' SQL Injection
CVE-2006-6802webappsasp
SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Enthrallweb eCars 1.0 - 'types.asp' SQL Injection
CVE-2006-6803webappsasp
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL comma
23RISK
open
ReferênciaVexDay Proof
Dragon Business Directory 3.01.12 - 'ID' SQL Injection
CVE-2006-6804webappsasp
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search D
23RISK
open
ReferênciaVexDay Proof
Enthrallweb eJobs - 'newsdetail.asp' SQL Injection
CVE-2006-6805webappsasp
SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Ananda Real Estate 3.4 - 'agent' SQL Injection
CVE-2006-6807webappsasp
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier all
23RISK
open
ReferênciaVexDay Proof
Bubla 1.0.0rc2 - '/bu/process.php' Remote File Inclusion
CVE-2006-6809webappsphp
Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla
23RISK
open
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
CVE-2006-6938webappsphp
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RISK
open
ReferênciaVexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
CVE-2006-6941webappsphp
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action
23RISK
open
ReferênciaVexDay Proof
SCart 2.0 - 'page' Remote Code Execution
CVE-2006-7012webappsphp
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RISK
open
ReferênciaVexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-7032webappsphp
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RISK
open
ReferênciaVexDay Proof
TinyPHP Forum 3.6 - 'profile.php' Remote Code Execution
CVE-2006-7063webappsphp
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and
23RISK
open
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
CVE-2006-7080webappsphp
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RISK
open
ReferênciaVexDay Proof
PhpNews 1.0 - 'Include' Remote File Inclusion
CVE-2006-7081webappsphp
Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code v
23RISK
open
ReferênciaVexDay Proof
PHPWind 5.0.1 - 'AdminUser' Blind SQL Injection
CVE-2006-7101webappsphp
SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
CVE-2006-7106webappsphp
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers t
23RISK
open
ReferênciaVexDay Proof
FreePBX 2.1.3 - 'upgrade.php' Remote File Inclusion
CVE-2006-7107webappsphp
PHP remote file inclusion vulnerability in upgrade.php in Coalescent Systems freePBX 2.1.3 allows remote attackers to ex
23RISK
open
ReferênciaVexDay Proof
MDPro 1.0.76 - 'Cookie PNSVlang' Local File Inclusion
CVE-2006-7112webappsphp
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read an
23RISK
open
ReferênciaVexDay Proof
TaskTracker 1.5 - 'Customize.asp' Remote Add Administrator
CVE-2007-0049webappsasp
Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add act
23RISK
open
ReferênciaVexDay Proof
AutoDealer 2.0 - 'detail.asp?iPro' SQL Injection
CVE-2007-0053webappsasp
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute
23RISK
open
ReferênciaVexDay Proof
IMGallery 2.5 - Create Uploader Script
CVE-2007-0082webappsphp
users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows
23RISK
open
previouspage 184 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.