Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,343cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Nevis Systems All-Mail 1.1 - Remote Buffer Overflow
CVE-2000-0985remotewindows10 Oct 2000
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO
23RISK
open
Exploit-DBVexDay Proof
Evolvable Shambala Server 4.5 - Denial of Service
CVE-2000-0953doswindows09 Oct 2000
Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
23RISK
open
Exploit-DBVexDay Proof
extropia webstore 1.0/2.0 - Directory Traversal
CVE-2000-1005remotecgi09 Oct 2000
Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remot
23RISK
open
Exploit-DBVexDay Proof
Bytes interactive Web shopper 1.0/2.0 - Directory Traversal
CVE-2000-0922remotecgi08 Oct 2000
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier a
23RISK
open
Exploit-DBVexDay Proof
phpix 1.0 - Directory Traversal
CVE-2000-0919webappsphp07 Oct 2000
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files
23RISK
open
Exploit-DBVexDay Proof
Hassan Consulting Shopping Cart 1.18 - Directory Traversal
CVE-2000-0921remotecgi07 Oct 2000
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read ar
23RISK
open
Exploit-DBVexDay Proof
RedHat 6.2/7.0 Tmpwatch - Arbitrary Command Execution
CVE-2000-0816locallinux06 Oct 2000
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain she
23RISK
open
Exploit-DBVexDay Proof
OpenBSD 2.x - Pending ARP Request Remote Denial of Service
CVE-2000-0914dosopenbsd05 Oct 2000
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Virtual Machine 2000/3100/3200/3300 Series - 'com.ms.activeX.ActiveXComponent' Arbitrary Program Execution
CVE-2000-1061remotewindows05 Oct 2000
Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX cont
28RISK
open
Exploit-DBVexDay Proof
OpenBSD 2.x - 'fstat' Format String
CVE-2000-0994localopenbsd04 Oct 2000
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - Indexed Directory Disclosure
CVE-2000-0951remotewindows04 Oct 2000
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list direc
35RISK
open
Exploit-DBVexDay Proof
David Harris Pegasus Mail 3.12 - File Forwarding
CVE-2000-0930remotewindows03 Oct 2000
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol wi
23RISK
open
Exploit-DBVexDay Proof
Cisco PIX Firewall 5.2 - PASV Mode FTP Internal Address Disclosure
CVE-2000-1027remotehardware03 Oct 2000
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by floo
23RISK
open
Exploit-DBVexDay Proof
Smartwin Technology CyberOffice Shopping Cart 2.0 - Price Modification
CVE-2000-0926remotewindows02 Oct 2000
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the
23RISK
open
Exploit-DBVexDay Proof
Moreover CGI script - File Disclosure
CVE-2000-0906remotecgi02 Oct 2000
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to re
23RISK
open
Exploit-DBVexDay Proof
SmartWin CyberOffice Shopping Cart 2.0 - Client Information Disclosure
CVE-2000-0925remotewindows02 Oct 2000
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with wo
23RISK
open
Exploit-DBVexDay Proof
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (2)
CVE-2000-1037remotemultiple01 Oct 2000
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus in
23RISK
open
Exploit-DBVexDay Proof
OpenSSH 1.2 - '.scp' File Create/Overwrite
CVE-2000-0992remotelinux30 Sep 2000
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary file
23RISK
open
Exploit-DBVexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (3)
CVE-2000-0949locallinux28 Sep 2000
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISK
open
Exploit-DBVexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (1)
CVE-2000-0949locallinux28 Sep 2000
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISK
open
Exploit-DBVexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (2)
CVE-2000-0949locallinux28 Sep 2000
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISK
open
Exploit-DBVexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (2)
CVE-2000-0573remotelinux26 Sep 2000
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISK
open
Exploit-DBVexDay Proof
Palm OS 3.5.2 - Weak Encryption
CVE-2000-1008localpalm_os26 Sep 2000
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Media Player 7 - Embedded OCX Control
CVE-2000-0929remotewindows26 Sep 2000
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embed
28RISK
open
Exploit-DBVexDay Proof
Unixware 7.0 - SCOhelp HTTP Server Format String
CVE-2000-1014remotecgi26 Sep 2000
Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attacker
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Script Host 5.1/5.5 - 'GetObject()' File Disclosure
CVE-2001-0149remotewindows26 Sep 2000
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetO
35RISK
open
Exploit-DBVexDay Proof
HP OpenView Network Node Manager 6.10 - SNMP Denial of Service
CVE-2000-1058dosmultiple26 Sep 2000
Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attacke
28RISK
open
Exploit-DBVexDay Proof
Alabanza Control Panel 3.0 - Domain Modification
CVE-2000-1023remotecgi24 Sep 2000
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
UoW Pine 4.0.4/4.10/4.21 - 'From:' Remote Buffer Overflow
CVE-2000-0909remotelinux23 Sep 2000
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arb
28RISK
open
Exploit-DBVexDay Proof
NetcPlus BrowseGate 2.80 - Denial of Service
CVE-2000-0908doswindows21 Sep 2000
BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Au
23RISK
open
previouspage 784 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.