Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
Microsoft JET 3.5/3.51/4.0 - VBA Shell
CVE-2000-0325remotewindows29 Jul 1999
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulne
23RISK
open
Exploit-DBVexDay Proof
Check Point Software Firewall-1 3.0/1 4.0 - Table Saturation Denial of Service
CVE-1999-0770doshardware29 Jul 1999
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to
23RISK
open
Exploit-DBVexDay Proof
Squid Web Proxy 2.2 - 'cachemgr.cgi' Unauthorized Connection
CVE-1999-0710remotecgi23 Jul 1999
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory
28RISK
open
Exploit-DBVexDay Proof
Samba < 2.0.5 - Local Overflow
CVE-1999-0811locallinux21 Jul 1999
Buffer overflow in Samba smbd program via a malformed message command.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
CVE-1999-1011remotewindows19 Jul 1999
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISK
open
Exploit-DBVexDay Proof
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)
CVE-1999-1011localwindows19 Jul 1999
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISK
open
Exploit-DBVexDay Proof
BSD/Linux Kernel 2.3 (BSD/OS 4.0 / FreeBSD 3.2 / NetBSD 1.4) - Shared Memory Denial of Service
CVE-1999-1518dosbsd15 Jul 1999
Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service a
23RISK
open
Exploit-DBVexDay Proof
BMC Software Patrol 3.2.5 - Patrol SNMP Agent File Creation/Permission
CVE-1999-1460locallinux14 Jul 1999
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying t
23RISK
open
Exploit-DBVexDay Proof
Caldera OpenUnix 8.0/UnixWare 7.1.1 / HP HP-UX 11.0 / Solaris 7.0 / SunOS 4.1.4 - rpc.cmsd Buffer Overflow (2)
CVE-1999-0696remotemultiple13 Jul 1999
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
28RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.0.37 - Segment Limit Privilege Escalation
CVE-1999-1166locallinux13 Jul 1999
Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by acce
23RISK
open
Exploit-DBVexDay Proof
Caldera OpenUnix 8.0/UnixWare 7.1.1 / HP HP-UX 11.0 / Solaris 7.0 / SunOS 4.1.4 - rpc.cmsd Buffer Overflow (1)
CVE-1999-0696remotemultiple13 Jul 1999
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
28RISK
open
Exploit-DBVexDay Proof
Apple Mac OS 8 8.6 - Weak Password Encryption
CVE-1999-1543localosx10 Jul 1999
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.
23RISK
open
Exploit-DBVexDay Proof
Netscape Enterprise Server 3.6 - SSL Buffer Overflow (Denial of Service) (PoC)
CVE-1999-0752doswindows06 Jul 1999
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 95/98 / NT Enterprise Server 4.0 SP5 / NT Terminal Server 4.0 SP4 / NT Workstation 4.0 SP5 - Denial of Service (1)
CVE-1999-0918doswindows03 Jul 1999
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
28RISK
open
Exploit-DBVexDay Proof
Microsoft Windows 95/98 / NT Enterprise Server 4.0 SP5 / NT Terminal Server 4.0 SP4 / NT Workstation 4.0 SP5 - Denial of Service (2)
CVE-1999-0918doswindows03 Jul 1999
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
28RISK
open
Exploit-DBVexDay Proof
mailx 8.1.1-10 (BSD/Slackware) - Local Buffer Overflow (2)
CVE-2000-0545locallinux03 Jul 1999
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (c
23RISK
open
Exploit-DBVexDay Proof
BSDI BSD/OS 4.0 /FreeBSD 3.2 /NetBSD 1.4 x86 / OpenBSD 2.5 - UFS Secure Level 1
CVE-1999-1394localbsd02 Jul 1999
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append
23RISK
open
Exploit-DBVexDay Proof
Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 - Null Session Admin Name
CVE-1999-0562doswindows28 Jun 1999
The registry in Windows NT can be accessed remotely by users who are not administrators.
28RISK
open
Exploit-DBVexDay Proof
VMware 1.0.1 - Local Buffer Overflow
CVE-1999-0733locallinux25 Jun 1999
Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
23RISK
open
Exploit-DBVexDay Proof
Xi Graphics Accelerated X 4.0.x/5.0 - Local Buffer Overflow
CVE-1999-0778locallinux25 Jun 1999
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query p
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 3.0/4.0 - Double Byte Code Page
CVE-1999-0725remotewindows24 Jun 1999
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source
28RISK
open
Exploit-DBVexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (1)
CVE-1999-0977remotesolaris24 Jun 1999
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISK
open
Exploit-DBVexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (2)
CVE-1999-0977remotesolaris24 Jun 1999
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISK
open
Exploit-DBVexDay Proof
Debian 2.1 - HTTPd
CVE-1999-0678remotelinux17 Jun 1999
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read
35RISK
open
Exploit-DBVexDay Proof
tcpdump 3.4 - Protocol Four / Zero Header Length
CVE-1999-1024remotelinux16 Jun 1999
ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length
23RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (4)
CVE-1999-0874remotewindows15 Jun 1999
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (3)
CVE-1999-0874remotelinux15 Jun 1999
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (2)
CVE-1999-0874remotewindows15 Jun 1999
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISK
open
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (1)
CVE-1999-0874remotewindows15 Jun 1999
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISK
open
Exploit-DBVexDay Proof
RedHat Linux 5.2 i386/6.0 - No Logging
CVE-2000-0118locallinux09 Jun 1999
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which
23RISK
open
previouspage 805 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.