Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,295cataloged exploits
36,048CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
PHP-Nuke Network Tool 0.2 Addon - MetaCharacter Filtering Command Execution
CVE-2001-0899remotephp16 Nov 2001
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the
23RISK
open
Exploit-DBVexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (1)
CVE-2001-0815remotelinux15 Nov 2001
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RISK
open
Exploit-DBVexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (3)
CVE-2001-0815remotemultiple15 Nov 2001
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RISK
open
Exploit-DBVexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (2)
CVE-2001-0815remotewindows15 Nov 2001
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RISK
open
Exploit-DBVexDay Proof
Opera 5.0/5.1 - Same Origin Policy Circumvention
CVE-2001-0898remotewindows15 Nov 2001
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domain
23RISK
open
Exploit-DBVexDay Proof
Rational ClearCase 3.2/4.x - DB Loader TERM Environment Variable Buffer Overflow
CVE-2001-0855localunix09 Nov 2001
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM env
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - Cookie Disclosure/Modification
CVE-2001-0722remotewindows09 Nov 2001
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, a
28RISK
open
Exploit-DBVexDay Proof
Horde IMP 2.2.x - Session Hijacking
CVE-2001-0857remotelinux09 Nov 2001
Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain acces
23RISK
open
Exploit-DBVexDay Proof
RedHat TUX 2.1.0-2 - HTTP Server Oversized Host Denial of Service
CVE-2001-0852doslinux05 Nov 2001
TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.
23RISK
open
Exploit-DBVexDay Proof
Sudo 1.6.x - Password Prompt Heap Overflow
CVE-2002-0184locallinux01 Nov 2001
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local user
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows XP/2000 - GDI Denial of Service
CVE-2001-1560doswindows29 Oct 2001
Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
iBill Management Script - Weak Hard-Coded Password
CVE-2001-0839remotecgi25 Oct 2001
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows
23RISK
open
Exploit-DBVexDay Proof
6Tunnel 0.6/0.7/0.8 - Connection Close State Denial of Service
CVE-2001-0830dosmultiple23 Oct 2001
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - JavaScript Interface Spoofing
CVE-2001-1410remotewindows21 Oct 2001
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createP
35RISK
open
Exploit-DBVexDay Proof
Mountain Network Systems WebCart 8.4 - Command Execution
CVE-2001-1502remotecgi19 Oct 2001
webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell meta
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.2/2.4 - Deep Symbolic Link Denial of Service
CVE-2001-0907doslinux18 Oct 2001
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a serie
23RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.2/2.4 - Ptrace/Setuid Exec Privilege Escalation
CVE-2001-1384locallinux18 Oct 2001
ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptr
23RISK
open
Exploit-DBVexDay Proof
Oracle9iAS Web Cache 2.0 - Remote Buffer Overflow
CVE-2001-0836remotewindows18 Oct 2001
Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET re
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT/2000 - Terminal Server Service RDP Denial of Service
CVE-2001-0663doswindows18 Oct 2001
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of in
35RISK
open
Exploit-DBVexDay Proof
Snes9x 1.3 - Local Buffer Overflow
CVE-2001-1015localunix16 Oct 2001
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long comman
23RISK
open
Exploit-DBVexDay Proof
PostNuke 0.6 - User Login
CVE-2001-1460webappsphp13 Oct 2001
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authenticatio
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - Zone Spoofing (MS01-055)
CVE-2001-0664remotewindows10 Oct 2001
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain d
28RISK
open
Exploit-DBVexDay Proof
Progress Database 8.3/9.1 - Multiple Buffer Overflows
CVE-2001-1127localmultiple05 Oct 2001
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RISK
open
Exploit-DBVexDay Proof
AmTote Homebet - World Accessible Log
CVE-2001-1170remotemultiple28 Sep 2001
AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote
23RISK
open
Exploit-DBVexDay Proof
Amtote Homebet - Account Information Brute Force
CVE-2001-1528remotemultiple28 Sep 2001
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
23RISK
open
Exploit-DBVexDay Proof
3Com OfficeConnect DSL Router 812 1.1.7/840 1.1.7 - HTTP Port Router Denial of Service
CVE-2001-0740doshardware21 Sep 2001
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attacker
23RISK
open
Exploit-DBVexDay Proof
FreeBSD 4.3/4.4 - Login Capabilities Privileged File Reading
CVE-2001-1029localfreebsd17 Sep 2001
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the
23RISK
open
Exploit-DBVexDay Proof
Microsoft Index Server 2.0 - File Information / Full Path Disclosure
CVE-2001-0986remotewindows14 Sep 2001
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as th
35RISK
open
Exploit-DBVexDay Proof
EFTP Server 2.0.7.337 - Directory Existence / File Existence
CVE-2001-1109remotewindows12 Sep 2001
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a
23RISK
open
Exploit-DBVexDay Proof
RedHat Linux 7.0 Apache - Remote Username Enumeration
CVE-2001-1013remotelinux12 Sep 2001
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RISK
open
previouspage 764 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.