Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
NetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password Encryption
CVE-2001-1354localmultiple20 Jul 2001
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses
23RISK
open
Exploit-DBVexDay Proof
Solaris 2.x/7.0/8 / IRIX 6.5.x / OpenBSD 2.x / NetBSD 1.x / Debian 3 / HP-UX 10 - 'TelnetD' Remote Buffer Overflow
CVE-2001-0554remoteunix18 Jul 2001
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbit
35RISK
open
Exploit-DBVexDay Proof
ID Software Quake 1.9 - Denial of Service
CVE-1999-1569dosmultiple17 Jul 2001
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconne
23RISK
open
Exploit-DBVexDay Proof
Check Point Firewall-1 4.x - SecuRemote Internal Interface Address Information Leakage
CVE-2003-0757doshardware17 Jul 2001
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces
23RISK
open
Exploit-DBVexDay Proof
Check Point Firewall-1 4 Securemote - Network Information Leak
CVE-2001-1303remotehardware17 Jul 2001
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configura
23RISK
open
Exploit-DBVexDay Proof
Interactive story 1.3 - Directory Traversal
CVE-2001-0804remotecgi15 Jul 2001
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files
23RISK
open
Exploit-DBVexDay Proof
Debian 2.2 /usr/bin/pileup - Local Privilege Escalation
CVE-2001-0989locallinux13 Jul 2001
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or
23RISK
open
Exploit-DBVexDay Proof
Microsoft Outlook 98/2000/2002 - Unauthorized Email Access
CVE-2001-0538remotewindows12 Jul 2001
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RISK
open
Exploit-DBVexDay Proof
Microsoft Outlook 98/2000/2002 - Arbitrary Code Execution
CVE-2001-0538remotewindows12 Jul 2001
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RISK
open
Exploit-DBVexDay Proof
3Com SuperStack II PS Hub 40 - TelnetD Weak Password Protection
CVE-2001-1291remotehardware12 Jul 2001
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide
23RISK
open
Exploit-DBVexDay Proof
ArGoSoft FTP Server 1.2.2.2 - Weak Password Encryption
CVE-2001-1142remotewindows12 Jul 2001
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the passwor
23RISK
open
Exploit-DBVexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (2)
CVE-2001-0735localunix11 Jul 2001
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISK
open
Exploit-DBVexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (3)
CVE-2001-0735localunix10 Jul 2001
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISK
open
Exploit-DBVexDay Proof
Apache 1.3 - Directory Index Disclosure
CVE-2001-0731remotemultiple10 Jul 2001
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a
35RISK
open
Exploit-DBVexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (1)
CVE-2001-1177localhardware10 Jul 2001
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISK
open
Exploit-DBVexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (3)
CVE-2001-1177localhardware10 Jul 2001
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISK
open
Exploit-DBVexDay Proof
xloadimage 4.1 - Remote Buffer Overflow
CVE-2001-0775remotelinux10 Jul 2001
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via
28RISK
open
Exploit-DBVexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (2)
CVE-2001-1177localhardware10 Jul 2001
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISK
open
Exploit-DBVexDay Proof
HP-UX 11 / Linux Kernel 2.4 / Windows 2000/NT 4.0 / IRIX 6.5 - Small TCP MSS Denial of Service
CVE-2001-1244dosmultiple07 Jul 2001
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by
28RISK
open
Exploit-DBVexDay Proof
Basilix Webmail 1.0 - File Disclosure
CVE-2001-1045webappsphp06 Jul 2001
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to re
23RISK
open
Exploit-DBVexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (2)
CVE-2001-0559locallinux05 Jul 2001
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RISK
open
Exploit-DBVexDay Proof
Cobalt Qube Webmail 1.0 - Directory Traversal
CVE-2001-1408webappsphp05 Jul 2001
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbit
23RISK
open
Exploit-DBVexDay Proof
Cobalt Raq3 PopRelayD - Arbitrary SMTP Relay
CVE-2001-1075remotelinux04 Jul 2001
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by caus
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
CVE-2001-1243doswindows04 Jul 2001
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISK
open
Exploit-DBVexDay Proof
Lmail 2.7 - Temporary File Race Condition
CVE-2001-1085locallinux04 Jul 2001
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Device File Remote Denial of Service
CVE-2001-1243doswindows04 Jul 2001
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISK
open
Exploit-DBVexDay Proof
Citrix Nfuse 1.51 - Webroot Disclosure
CVE-2001-0760webappsasp02 Jul 2001
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.
23RISK
open
Exploit-DBVexDay Proof
Xvt 2.1 - Local Buffer Overflow
CVE-2001-1561locallinux02 Jul 2001
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -
23RISK
open
Exploit-DBVexDay Proof
PHP 4.x - SafeMode Arbitrary File Execution
CVE-2001-1246localphp30 Jun 2001
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows lo
23RISK
open
Exploit-DBVexDay Proof
Active Classifieds 1.0 - Arbitrary Code Execution
CVE-2001-1290remotecgi28 Jun 2001
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify th
23RISK
open
previouspage 767 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.