Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Invalid Byte Cross-Frame Access
CVE-1999-0347—remotewindows28 Jan 1999
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "abou
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - IISAPI Extension Enumerate Root Web Server Directory
CVE-1999-0450—remotewindows26 Jan 1999
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - 'ldd core' Force Reboot (Denial of Service)
CVE-1999-0400—doslinux26 Jan 1999
Denial of service in Linux 2.2.0 running the ldd command on a core file.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4 (Windows NT) - Log Avoidance
CVE-1999-0448—remotewindows22 Jan 1999
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4 - Clipboard Paste
CVE-1999-1453—remotewindows21 Jan 1999
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.0 - TCP Port Denial of Service
CVE-1999-0451—doslinux19 Jan 1999
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4 (Windows NT) - Remote Web-Based Administration
CVE-1999-1538—remotewindows14 Jan 1999
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Cisco IOS 12.0.2 - Syslog Crash
CVE-1999-0063—doshardware11 Jan 1999
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Zero Administration Kit (ZAK) 1.0 / Office97 - Backdoor Access
CVE-1999-1431—localwindows07 Jan 1999
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 app
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sun Solaris 7.0 - 'ff.core' Local Privilege Escalation
CVE-1999-0442—localsolaris07 Jan 1999
Solaris ff.core allows local users to modify files.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DataLynx suGuard 1.0 - Local Privilege Escalation
CVE-1999-0388—locallinux03 Jan 1999
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute command
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Stanford University bootpd 2.4.3 / Debian 2.0 - netstd
CVE-1999-0914—locallinux03 Jan 1999
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SSH - User Code Execution (Metasploit)
CVE-1999-0502—remotemultiple01 Jan 1999
A Unix account has a default, null, blank, or missing password.
50RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 7.0 - 'ufsdump' Local Buffer Overflow (2)
CVE-1999-0069HIGHlocalsolaris30 Dec 1998
Solaris ufsrestore buffer overflow.
41RISK
open ↗
Exploit-DB✓ VexDay Proof
SCO UNIX 5 calserver - Remote Buffer Overflow
CVE-2000-0306—remotesco29 Dec 1998
Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
BNC 2.2.4/2.4.6/2.4.8 - IRC Proxy Buffer Overflow (2)
CVE-1999-0968—remoteunix26 Dec 1998
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
BNC 2.2.4/2.4.6/2.4.8 - IRC Proxy Buffer Overflow (1)
CVE-1999-0968—remoteunix26 Dec 1998
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0 - Remote File Display / Deletion / Upload / Execution
CVE-1999-0455—remotemultiple25 Dec 1998
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0 - Remote File Display / Deletion / Upload / Execution
CVE-1999-0477—remotemultiple25 Dec 1998
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 2.5.1 - 'kcms' Local Buffer Overflow (2)
CVE-1999-0321—localsolaris24 Dec 1998
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 2.5.1 - 'kcms' Local Buffer Overflow (1)
CVE-1999-0321—localsolaris24 Dec 1998
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Greg Matthews - 'Classifieds.cgi' 1.0 MetaCharacter
CVE-1999-0934—remotecgi15 Dec 1998
classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Greg Matthews - 'Classifieds.cgi' 1.0 Hidden Variable
CVE-1999-0935—remotecgi15 Dec 1998
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI f
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.9.2 - Headers Prescan Denial of Service
CVE-1999-0393—dosirix12 Dec 1998
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of he
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SCO Unixware 7.0/7.0.1/7.1/7.1.1 - 'uidadmin' Local Privilege Escalation
CVE-1999-0836—localsco02 Dec 1998
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Novell Netware Web Server 3.x - files.pl
CVE-1999-1081—remotenovell01 Dec 1998
Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IBM AIX 4.3 - 'infod' Local Privilege Escalation
CVE-1999-0118—localaix21 Nov 1998
AIX infod allows local users to gain root access through an X display.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
IRIX 6.2/6.3 - '/bin/lpstat' Local Buffer Overflow
CVE-2000-0795—localirix01 Nov 1998
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sun Solaris 7.0 - '/usr/dt/bin/sdtcm_convert' Local Overflow / Local Privilege Escalation
CVE-1999-0369—localsolaris23 Oct 1998
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SGI IRIX 3/4/5/6 / OpenLinux 1.0/1.1 - routed traceon
CVE-1999-0215—remoteirix21 Oct 1998
Routed allows attackers to append data to files.
23RISK
open ↗
← previouspage 629 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.