Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
PHP 3.0.13 - 'Safe_mode' Failure
CVE-2000-0059—remotephp04 Jan 2000
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, whic
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0/4.0.1 - 'CFCACHE' Information Disclosure
CVE-2000-0057—remotemultiple04 Jan 2000
Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain s
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solution Scripts Home Free 1.0 - 'search.cgi' Directory Traversal
CVE-2000-0054—remotecgi03 Jan 2000
search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attac
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10 / HP-UX 9/10/11 / Mandriva 6/7 / RedHat 5/6 / SCO 5 / IRIX 6 - Shell Redirection Race Condition
CVE-2000-1134—localunix02 Jan 2000
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Phorum 3.0.7 - 'violation.php3' Arbitrary Email Relay
CVE-2000-1234—webappsphp01 Jan 2000
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IRIX 6.5.x - '/usr/lib/InPerson/inpview' Race Condition
CVE-2000-0799—localirix01 Jan 2000
inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on th
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SGI IRIX 6.2 - 'midikeys'/'soundplayer' Local Privilege Escalation
CVE-2000-0013—localirix31 Dec 1999
IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which i
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Netscape FastTrack Server 2.0.1a - GET Buffer Overflow
CVE-1999-0744—remoteunixware31 Dec 1999
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long
23RISK
open ↗
Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.1 - GET Buffer Overflow
CVE-2000-0011—doswindows31 Dec 1999
Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET reque
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Ascend CascadeView/UX 1.0 tftpd - Symbolic Link
CVE-2000-0015—localunix31 Dec 1999
CascadeView TFTP server allows local users to gain privileges via a symlink attack.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Nortel Networks Optivity NETarchitect 2.0 - PATH
CVE-2000-0009—localmultiple30 Dec 1999
The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
BroadGun Software CamShot WebCam 2.5 - GET Buffer Overflow
CVE-2000-0043—doswindows30 Dec 1999
Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
AltaVista Search Intranet 2.0 b/2.3 - Directory Traversal
CVE-2000-0039—remoteunix29 Dec 1999
AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cg
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Majordomo 1.94.4/1.94.5 - Local -C Parameter (2)
CVE-2000-0037—locallinux29 Dec 1999
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Majordomo 1.94.4/1.94.5 - Local -C Parameter (1)
CVE-2000-0037—locallinux29 Dec 1999
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Systems Management Server 2.0 - Default Permissions
CVE-2000-0100—localwindows29 Dec 1999
The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by mo
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Michael Lamont Savant Web Server 2.0 - NULL Character Denial of Service
CVE-2000-0014—doswindows28 Dec 1999
Denial of service in Savant web server via a null character in the requested URL.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Great Circle Associates Majordomo 1.94.4 - Local resend
CVE-2000-0035—locallinux28 Dec 1999
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IBM Network Station Manager 2.0 R1 - Race Condition
CVE-2000-0027—localunix27 Dec 1999
IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Tony Greenwood WebWho+ 1.1 - Remote Command Execution
CVE-2000-0010—remotemultiple26 Dec 1999
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
ZBServer Pro 1.5 - Remote Buffer Overflow (1)
CVE-2000-0002—remotewindows23 Dec 1999
Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
glFTPd 1.17.2 - Code Execution
CVE-2000-0038—remoteunix23 Dec 1999
glFtpD includes a default glftpd user account with a default password and a UID of 0.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ZBServer Pro 1.5 - Remote Buffer Overflow (2)
CVE-2000-0002—remotewindows23 Dec 1999
Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Real Networks Real Server 5.0 - ramgen Denial of Service
CVE-2000-0001—dosfreebsd23 Dec 1999
RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SCO Unixware 7.1 - i2odialogd Remote Buffer Overflow
CVE-2000-0026—remotesco22 Dec 1999
Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password a
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 7.0 - DMI Denial of Service
CVE-2000-0032—dossolaris22 Dec 1999
Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4/5/5.5/5.0.1 - external.NavigateAndFind() Cross-Frame
CVE-2000-0028—remotemultiple22 Dec 1999
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the
28RISK
open ↗
Exploit-DB✓ VexDay Proof
McAfee 4.0 / Network Associates for Windows NT 4.0.2/4.0.3 a / Norton AntiVirus 2000 - Recycle Bin Exclusion
CVE-2000-0119—localwindows22 Dec 1999
The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Windowmaker wmmon 1.0 b2 - Command Execution
CVE-2000-0018—localfreebsd22 Dec 1999
wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Eric Allman Sendmail 8.9.1/8.9.3 - ETRN Denial of Service
CVE-1999-1109—doslinux22 Dec 1999
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then di
23RISK
open ↗
← previouspage 618 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.