Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Atrium Software Mercur Mail Server 3.2 - Multiple Buffer Overflows (1)
CVE-2000-0198doswindows14 Mar 2000
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of se
23RISK
open
Exploit-DBVexDay Proof
Atrium Software Mercur Mail Server 3.2 - Multiple Buffer Overflows (2)
CVE-2000-0198doswindows14 Mar 2000
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of se
23RISK
open
Exploit-DBVexDay Proof
Halloween Linux 4.0 / RedHat Linux 6.1/6.2 - 'imwheel' (1)
CVE-2000-0230locallinux13 Mar 2000
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME enviro
23RISK
open
Exploit-DBVexDay Proof
Sam Hawker wmcdplay 1.0 beta1-2 - Local Buffer Overflow (2)
CVE-2000-0223locallinux13 Mar 2000
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges
23RISK
open
Exploit-DBVexDay Proof
Halloween Linux 4.0 / RedHat Linux 6.1/6.2 - 'imwheel' (2)
CVE-2000-0230locallinux13 Mar 2000
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME enviro
23RISK
open
Exploit-DBVexDay Proof
Sam Hawker wmcdplay 1.0 beta1-2 - Local Buffer Overflow (1)
CVE-2000-0223locallinux11 Mar 2000
Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges
23RISK
open
Exploit-DBVexDay Proof
AT Computing atsar_linux 1.4 - File Manipulation
CVE-2000-0171locallinux11 Mar 2000
atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local user
23RISK
open
Exploit-DBVexDay Proof
Mirabilis ICQ 0.99/98.0 a/2000.0 A/99a - Remote Denial of Service
CVE-2000-1078doscgi10 Mar 2000
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" charact
23RISK
open
Exploit-DBVexDay Proof
Michael Sandrof IrcII 4.4-7 - Remote Buffer Overflow
CVE-2000-0183remotelinux10 Mar 2000
Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.
23RISK
open
Exploit-DBVexDay Proof
Sun StarOffice 5.1 - Arbitrary File Read
CVE-2000-0174remoteunix09 Mar 2000
StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0 - User Shell Folders
CVE-1999-1084localwindows09 Mar 2000
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify
23RISK
open
Exploit-DBVexDay Proof
GameHouse dldisplay - ActiveX control 0 / Real Server 5.0/7.0 Internal IP Address Disclosure
CVE-2000-0185remotewindows08 Mar 2000
RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.
23RISK
open
Exploit-DBVexDay Proof
WorldView 6.5/Wnn4 4.2 - Asian Language Server Remote Buffer Overflow
CVE-2000-0704remoteunix08 Mar 2000
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MK
28RISK
open
Exploit-DBVexDay Proof
Microsoft Clip Art Gallery 5.0 - Local Buffer Overflow
CVE-2000-0200localwindows06 Mar 2000
Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands v
28RISK
open
Exploit-DBVexDay Proof
Caldera OpenLinux 2.3 - rpm_query CGI
CVE-2000-0192remotecgi05 Mar 2000
The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to d
23RISK
open
Exploit-DBVexDay Proof
Oracle8i Standard Edition 8.1.5 for Linux Installer - Local Privilege Escalation
CVE-2000-0206locallinux05 Mar 2000
The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable pe
23RISK
open
Exploit-DBVexDay Proof
SGI InfoSearch 1.0 / SGI IRIX 6.5.x - fname
CVE-2000-0207remoteirix05 Mar 2000
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows Server 2000/95/98/ME/NT 3.5.x/Enterprise Server 4.0/Terminal Server 4.0/Workstation 4.0 Microsoft DoS Device Name - Denial of Service
CVE-2000-0168doswindows04 Mar 2000
Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file
28RISK
open
Exploit-DBVexDay Proof
Matt Kimball and Roger Wolff mtr 0.28/0.41 / Turbolinux 3.5 b2/4.2/4.4/6.0 - mtr (2)
CVE-2000-0172localmultiple03 Mar 2000
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root
23RISK
open
Exploit-DBVexDay Proof
DNSTools Software DNSTools 1.0.8/1.10 - Input Validation
CVE-2000-0177remotecgi02 Mar 2000
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
23RISK
open
Exploit-DBVexDay Proof
Corel Linux OS 1.0 - Dosemu Distribution Configuration
CVE-2000-0193locallinux02 Mar 2000
The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain pri
23RISK
open
Exploit-DBVexDay Proof
Axis Communications StorPoint CD - Authentication Bypass
CVE-2000-0191remotemultiple01 Mar 2000
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.
28RISK
open
Exploit-DBVexDay Proof
NetWin DNews 5.3 Server - Remote Buffer Overflow
CVE-2000-0423remotewindows01 Mar 2000
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters
23RISK
open
Exploit-DBVexDay Proof
The ht://Dig Group ht://Dig 3.1.1/3.1.2/3.1.3/3.1.4/3.2 .0b1 - Arbitrary File Inclusion
CVE-2000-0208remoteunix29 Feb 2000
The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name wit
23RISK
open
Exploit-DBVexDay Proof
HP OpenView OmniBack II 2.55/3.0/3.1 - Denial of Service
CVE-2000-0179doswindows28 Feb 2000
HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port
23RISK
open
Exploit-DBVexDay Proof
Alex Heiphetz Group eZshopper 3.0 - Remote Command Execution
CVE-2000-0187remotemultiple27 Feb 2000
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execu
23RISK
open
Exploit-DBVexDay Proof
Trend Micro OfficeScan Corporate Edition 3.0/3.5/3.11/3.13 - Denial of Service
CVE-2000-0204dosmultiple26 Feb 2000
The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 1
23RISK
open
Exploit-DBVexDay Proof
RedHat 4.x/5.x/6.x / RedHat man 1.5 / Turbolinux man 1.5 / Turbolinux 3.5/4.x - 'man' Buffer Overrun (2)
CVE-2000-0170locallinux26 Feb 2000
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variabl
23RISK
open
Exploit-DBVexDay Proof
RedHat 4.x/5.x/6.x / RedHat man 1.5 / Turbolinux man 1.5 / Turbolinux 3.5/4.x - 'man' Buffer Overrun (1)
CVE-2000-0170locallinux26 Feb 2000
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variabl
23RISK
open
Exploit-DBVexDay Proof
Nortel Networks Nautica Marlin - Denial of Service
CVE-2000-0221doshardware25 Feb 2000
The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP
23RISK
open
previouspage 795 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.