Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,324cataloged exploits
36,054CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
SunOS 5.7 Catman - Local Insecure tmp Symlink Clobber
CVE-2001-0095dossolaris20 Dec 2000
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISK
open
Exploit-DBVexDay Proof
Brian Stanback bsguest.cgi 1.0 - Remote Command Execution
CVE-2001-0099remotecgi20 Dec 2000
bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email
28RISK
open
Exploit-DBVexDay Proof
Brian Stanback bslist.cgi 1.0 - Remote Command Execution
CVE-2001-0100remotecgi20 Dec 2000
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the ema
28RISK
open
Exploit-DBVexDay Proof
ProFTPd 1.2 - 'SIZE' Remote Denial of Service
CVE-2001-0136doslinux20 Dec 2000
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and
35RISK
open
Exploit-DBVexDay Proof
OpenBSD ftpd 2.6/2.7 - Remote Overflow
CVE-2001-0053remotebsd20 Dec 2000
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
28RISK
open
Exploit-DBVexDay Proof
BEA Systems WebLogic Server 4.0 x/4.5 x/5.1 x - Double Dot Buffer Overflow
CVE-2001-0098remotemultiple19 Dec 2000
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL
45RISK
open
Exploit-DBVexDay Proof
Solaris 2.7/2.8 Catman - Local Insecure tmp Symlink
CVE-2001-0095doswindows19 Dec 2000
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISK
open
Exploit-DB
BOA Web Server 0.94.8.2 - Arbitrary File Access
CVE-2000-0920webappslinux19 Dec 2000
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files
23RISK
open
Exploit-DBVexDay Proof
Itetris 1.6.1/1.6.2 - Privileged Arbitrary Command Execution
CVE-2001-0087locallinux19 Dec 2000
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which
23RISK
open
Exploit-DBVexDay Proof
BSD ftpd 0.3.2 - Single Byte Buffer Overflow
CVE-2001-0053remoteunix18 Dec 2000
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
28RISK
open
Exploit-DBVexDay Proof
Solaris 2.5.1/2.6/7.0/8 - patchadd Race Condition
CVE-2001-0059localsolaris18 Dec 2000
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
23RISK
open
Exploit-DBVexDay Proof
xsoldier 0.96 (RedHat 6.2) - Local Buffer Overflow
CVE-1999-1008locallinux15 Dec 2000
xsoldier program allows local users to gain root access via a long argument.
23RISK
open
Exploit-DBVexDay Proof
Oops! 1.4.6 - one russi4n proxy-server Heap Buffer Overflow
CVE-2001-0029remotebsd15 Dec 2000
Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrar
23RISK
open
Exploit-DBVexDay Proof
LPRng 3.6.24-1 - Remote Command Execution
CVE-2000-0917remotelinux15 Dec 2000
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
Leif M. Wright simplestguest.cgi 2.0 - Remote Command Execution
CVE-2001-0022remotecgi14 Dec 2000
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharact
28RISK
open
Exploit-DBVexDay Proof
Check Point Software Firewall-1 4.1 SP2 - Fast Mode TCP Fragment
CVE-2001-0082remotemultiple14 Dec 2000
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via mal
23RISK
open
Exploit-DBVexDay Proof
Cisco Catalyst 4000/5000/6000 6.1 - SSH Protocol Mismatch Denial of Service
CVE-2001-0080doshardware13 Dec 2000
Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH
23RISK
open
Exploit-DBVexDay Proof
alex heiphetz Group eZshopper 2.0/3.0 - Directory Traversal
CVE-2000-1092remotemultiple13 Dec 2000
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data d
23RISK
open
Exploit-DBVexDay Proof
AOL Instant Messenger 4.0/4.1.2010/4.2.1193 - BuddyIcon Buffer Overflow
CVE-2000-1094remotewindows12 Dec 2000
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via
23RISK
open
Exploit-DBVexDay Proof
AOL Instant Messenger 3.5.1856/4.0/4.1.2010/4.2.1193 - 'aim://' Remote Buffer Overflow
CVE-2000-1093remotewindows12 Dec 2000
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a lon
23RISK
open
Exploit-DBVexDay Proof
Leif M. Wright everythingform.cgi 2.0 - Arbitrary Command Execution
CVE-2001-0023remotecgi11 Dec 2000
everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharac
28RISK
open
Exploit-DBVexDay Proof
Oops Proxy Server 1.4.22 - Remote Buffer Overflow (1)
CVE-2001-0028remoteunix11 Dec 2000
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute a
23RISK
open
Exploit-DBVexDay Proof
Leif M. Wright - 'ad.cgi' 1.0 Unchecked Input
CVE-2001-0025remotecgi11 Dec 2000
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISK
open
Exploit-DBVexDay Proof
Leif M. Wright simplestmail.cgi 1.0 - Remote Command Execution
CVE-2001-0024remotecgi11 Dec 2000
simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacte
23RISK
open
Exploit-DBVexDay Proof
RedHat Linux 7.0 - Roaring Penguin PPPoE Denial of Service
CVE-2001-0026doslinux11 Dec 2000
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet wit
23RISK
open
Exploit-DBVexDay Proof
LPRng 3.6.22/23/24 - Remote Command Execution
CVE-2000-0917remotelinux11 Dec 2000
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
ssldump 0.9 b1 - Format String
CVE-2001-0032remoteunix11 Dec 2000
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain r
23RISK
open
Exploit-DBVexDay Proof
University of Washington Pico 3.x/4.x - File Overwrite
CVE-2001-0736locallinux11 Dec 2000
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to ove
23RISK
open
Exploit-DBVexDay Proof
LPRng (RedHat 7.0) - 'lpd' Format String
CVE-2000-0917remotelinux11 Dec 2000
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISK
open
Exploit-DBVexDay Proof
KTH Kerberos 4 - Arbitrary Proxy Usage
CVE-2001-0034remotemultiple08 Dec 2000
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to
23RISK
open
previouspage 779 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.