Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Resolv+ 'RESOLV_HOST_CONF' - Linux Library Command Execution
CVE-2001-0170—locallinux01 Jan 1996
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
23RISK
open ↗
Exploit-DB✓ VexDay Proof
John S.2 Roberts AnyForm 1.0/2.0 - CGI Semicolon
CVE-1999-0066CRITICALremotelinux31 Jul 1995
AnyForm CGI remote execution.
53RISK
open ↗
Exploit-DB✓ VexDay Proof
IRIX 5.2/6.0 - Permissions File Manipulation
CVE-1999-1243—localirix02 Mar 1995
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and
23RISK
open ↗
Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
CVE-1999-0235—remotelinux17 Feb 1995
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
CVE-1999-0267—remotelinux17 Feb 1995
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
SGI IRIX 6.0.1 - 'colorview' Read Files
CVE-1999-1494—localirix09 Feb 1995
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argume
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Majordomo 1.89/1.90 - 'lists' Command Execution
CVE-1999-0207—remotelinux06 Jun 1994
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.6.9 IDENT - Remote Command Execution
CVE-1999-0204—remoteunix24 Feb 1994
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (1)
CVE-1999-0208—remotemultiple07 Feb 1994
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (2)
CVE-1999-0208—remotemultiple07 Feb 1994
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
SGI IRIX 5.2/5.3 - 'serial_ports' Local Privilege Escalation
CVE-1999-1022—localirix02 Feb 1994
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execut
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SunOS 4.1.4 - arp(8c) Memory Dump
CVE-1999-0859—localsolaris01 Feb 1994
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse prope
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Digital Ultrix 4.0/4.1 - '/usr/bin/chroot' Local Privilege Escalation
CVE-1999-1194—localaix01 May 1991
chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
SunView (SunOS 4.1.1) - 'selection_svc' Remote File Read
CVE-1999-0209—remotesolaris14 Aug 1990
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RISK
open ↗
Exploit-DB✓ VexDay Proof
Intel Corporation Express 8100 ISDN Router - Fragmented ICMP
CVE-2000-0451—remotehardware19 May 1990
The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Berkeley Sendmail 5.58 - Debug
CVE-1999-0095—remotelinux01 Aug 1988
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
28RISK
open ↗
← previouspage 636 / 636

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.