Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,524cataloged exploits
37,962CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (1)
CVE-2001-1078—doslinux21 Jun 2001
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Cerberus FTP Server 1.x - Buffer Overflow (Denial of Service) (PoC)
CVE-2001-0702—doswindows21 Jun 2001
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code,
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow (MS03-051) (Metasploit)
CVE-2001-0341—remotewindows21 Jun 2001
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (2)
CVE-2001-0500—remotewindows21 Jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗
Exploit-DB✓ VexDay Proof
W3M 0.1/0.2 - Malformed MIME Header Buffer Overflow
CVE-2001-0700—remotefreebsd19 Jun 2001
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MI
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Internet Software Solutions Air Messenger LAN Server 3.4.2 - Full Path Disclosure
CVE-2001-0788—remotewindows18 Jun 2001
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute pat
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microburst uDirectory 2.0 - Remote Command Execution
CVE-2001-1160—remotecgi18 Jun 2001
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary command
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DC Scripts DCShop Beta 1.0 02 - File Disclosure (2)
CVE-2001-0821—remotecgi18 Jun 2001
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (3)
CVE-2001-0500—remotewindows18 Jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (PoC)
CVE-2001-0500—doswindows18 Jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗
Exploit-DB✓ VexDay Proof
DC Scripts DCShop Beta 1.0 02 - File Disclosure (1)
CVE-2001-0821—remotecgi18 Jun 2001
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 3.x - 'TTAWebTop.cgi' Arbitrary File Viewing
CVE-2001-0805—remotecgi18 Jun 2001
Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to rea
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SGI Performance Co-Pilot 2.1.x/2.2 - pmpost Symbolic Link
CVE-2001-0823—localirix18 Jun 2001
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink att
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (4)
CVE-2001-0500—remotewindows18 Jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISK
open ↗
Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
CVE-2002-1904—remotelinux17 Jun 2001
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbi
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
CVE-2001-0820—remotelinux17 Jun 2001
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Rxvt 2.6.1/2.6.2 - Local Buffer Overflow
CVE-2001-1077—locallinux15 Jun 2001
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name
23RISK
open ↗
Exploit-DB✓ VexDay Proof
NetSQL 1.0 - Remote Buffer Overflow
CVE-2001-1163—remotelinux15 Jun 2001
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT ar
28RISK
open ↗
Exploit-DB✓ VexDay Proof
BestCrypt 0.6/0.7/0.8 - BCTool UMount Buffer Overflow
CVE-2001-0759—locallinux14 Jun 2001
Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Juergen Schoenwaelder scotty 2.1.x - ntping Buffer Overflow
CVE-2001-0764—localunix13 Jun 2001
Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
CVE-2001-0925—remotemultiple13 Jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
CVE-2001-0925—remotemultiple13 Jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
CVE-2001-0925—remotemultiple13 Jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISK
open ↗
Exploit-DB✓ VexDay Proof
SiteWare 2.5/3.0/3.1 Editor Desktop - Directory Traversal
CVE-2001-0555—webappsjava13 Jun 2001
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot do
28RISK
open ↗
Exploit-DB✓ VexDay Proof
MDBms 0.96/0.99 - Query Display Buffer Overflow
CVE-2001-0818—remotelinux12 Jun 2001
A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary comm
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Rumpus FTP Server 1.3.x/2.0.3 - Stack Overflow Denial of Service
CVE-2001-0706—dososx12 Jun 2001
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir comma
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.0/1.3/1.4 - CGI File Creation
CVE-2000-0639—localcgi11 Jun 2001
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows rem
23RISK
open ↗
Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3.2 XMan - ManPath Environment Variable Buffer Overflow
CVE-2001-1178—locallinux11 Jun 2001
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
TransSoft Broker FTP Server 3.0/4.0/4.7/5.x - CWD Buffer Overflow
CVE-2001-0688—remotewindows10 Jun 2001
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or C
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apache 1.3.14 - Mac File Protection Bypass
CVE-2001-0766—remoteosx10 Jun 2001
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a UR
23RISK
open ↗
← previouspage 589 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.