Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,794cataloged exploits
36,057CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
FTPx FTP Explorer 1.0.00.10 - Weak Password Encryption
CVE-2000-0214locallinux25 Feb 2000
FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.
23RISK
open
Exploit-DBVexDay Proof
Pragma Systems InterAccess TelnetD Server 4.0 - Terminal Configuration
CVE-2000-0212doswindows24 Feb 2000
InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client conf
23RISK
open
Exploit-DBVexDay Proof
Sambar Server 4.2 Beta 7 - Batch CGI
CVE-2000-0213remotewindows24 Feb 2000
The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to exec
23RISK
open
Exploit-DBVexDay Proof
Corel Linux OS 1.0 - 'setxconf' Local Privilege Escalation
CVE-2000-0195locallinux24 Feb 2000
setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverr
23RISK
open
Exploit-DBVexDay Proof
Corel Linux OS 1.0 - buildxconfig
CVE-2000-0194locallinux24 Feb 2000
buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.
23RISK
open
Exploit-DBVexDay Proof
RedHat Linux 6.0 - Single User Mode Authentication
CVE-2000-0219locallinux23 Feb 2000
Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.
23RISK
open
Exploit-DBVexDay Proof
Pragma Systems InterAccess TelnetD Server 4.0 Build 4 - Buffer Overflow
CVE-2000-0166doswindows21 Feb 2000
Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login na
23RISK
open
Exploit-DBVexDay Proof
Sun Workshop 5.0 - Licensing Manager Symlink
CVE-2000-0210localsolaris21 Feb 2000
The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary file
23RISK
open
Exploit-DBVexDay Proof
FreeBSD 3.0/3.1/3.2/3.3/3.4 - 'Asmon'/'Ascpu' Local Privilege Escalation
CVE-2000-0163localfreebsd19 Feb 2000
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 95/98/NT 4.0 - 'autorun.inf' Code Execution
CVE-2000-0155localwindows18 Feb 2000
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alte
23RISK
open
Exploit-DBVexDay Proof
SCO Unixware 7.1/7.1.1 - ARCserver /tmp Symlink
CVE-2000-0154localsco15 Feb 2000
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.
23RISK
open
Exploit-DBVexDay Proof
SCO Unixware 7.1/7.1.1 - ARCserver /tmp Symlink
CVE-2000-0224localsco15 Feb 2000
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
23RISK
open
Exploit-DBVexDay Proof
MySQL 3.22.27/3.22.29/3.23.8 - GRANT Global Password Changing
CVE-2000-0045localmultiple15 Feb 2000
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - Pickup Directory Denial of Service
CVE-2000-0167doswindows15 Feb 2000
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml
23RISK
open
Exploit-DBVexDay Proof
Netopia Timbuktu Pro Remote Control 2.0/5.2.1 - Denial of Service
CVE-2000-0142dosmultiple11 Feb 2000
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections
23RISK
open
Exploit-DBVexDay Proof
True North Software Internet Anywhere Mail Server 3.1.3 - RETR Denial of Service
CVE-2000-0139doswindows10 Feb 2000
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
23RISK
open
Exploit-DBVexDay Proof
Zeus Web Server 3.x - Null Terminated Strings
CVE-2000-0149remotecgi08 Feb 2000
Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end o
23RISK
open
Exploit-DBVexDay Proof
Novell Groupwise Enhancement Pack 5.5 Enhancement Pack - Denial of Service
CVE-2000-0146dosnovell07 Feb 2000
The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service
23RISK
open
Exploit-DBVexDay Proof
Novell BorderManager 3.0/3.5 Audit Trail Proxy - Denial of Service
CVE-2000-0152dosnovell04 Feb 2000
Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connect
23RISK
open
Exploit-DBVexDay Proof
Daniel Beckham The Finger Server 0.82 Beta - Pipe
CVE-2000-0128remotecgi04 Feb 2000
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.
23RISK
open
Exploit-DBVexDay Proof
Cat Soft Serv-U FTP Server 2.5/a/b (Windows 95/98/2000/NT 4.0) - Shortcut
CVE-2000-0129remotewindows04 Feb 2000
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of servi
23RISK
open
Exploit-DBVexDay Proof
Jgaa WarFTPd 1.66 x4s/1.67-3 - 'CWD/MKD' Denial of Service
CVE-2000-0131doswindows03 Feb 2000
Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.
23RISK
open
Exploit-DBVexDay Proof
Wired Community Software WWWThreads 5.0 - SQL Command Input
CVE-2000-0125remotecgi03 Feb 2000
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote att
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 - Directory Traversal (MS00-006)
CVE-2000-0126remotemultiple02 Feb 2000
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
35RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0 - Recycle Bin Pre-created Folder
CVE-2000-0121localwindows01 Feb 2000
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirec
23RISK
open
Exploit-DBVexDay Proof
H. Nomura Tiny FTPDaemon 0.52 - Multiple Buffer Overflow Vulnerabilities
CVE-2000-0133remotewindows01 Feb 2000
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD,
23RISK
open
Exploit-DBVexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
CVE-2000-0105remotewindows01 Feb 2000
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that
28RISK
open
Exploit-DBVexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
CVE-2000-0653remotewindows01 Feb 2000
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the
28RISK
open
Exploit-DBVexDay Proof
QuickCommerce 2.5/3.0 / Cart32 2.5 a/3.0 / Shop Express 1.0 / StoreCreator 3.0 Web Shopping Cart - Hidden Form Field
CVE-2000-0136remotecgi01 Feb 2000
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields
23RISK
open
Exploit-DBVexDay Proof
Debian 2.1 - apcd Symlink
CVE-2000-0107locallinux01 Feb 2000
Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.
23RISK
open
previouspage 796 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.