HORKimhab

260 exploits Active since Oct 1988
CVE-1999-0099 GITHUB shell STUB
BSD/OS - Buffer Overflow in Syslog Utility
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVE-1999-0051 GITHUB shell STUB
FLEXlm 4.0-5.0 - Arbitrary File Creation and Program Execution
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
CVE-1999-0065 GITHUB shell STUB
Solaris - Remote Code Execution via dtmail Attachment Handling
Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.
CVE-2026-29014 GITHUB CRITICAL shell STUB
MetInfo CMS 7.9-8.1 - Unauthenticated PHP Code Injection
MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary code by sending crafted requests with malicious PHP code. Attackers can exploit insufficient input neutralization in the execution path to achieve remote code execution and gain full control over the affected server.
CVSS 9.8
CVE-2026-3395 GITHUB HIGH shell WRITEUP
MaxSite CMS <109.1 - Code Injection
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.
CVSS 7.3
CVE-2026-56291 GITHUB CRITICAL shell STUB
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
CVSS 9.8
CVE-1999-0093 GITHUB shell STUB
AIX nslookup - Privilege Escalation
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
CVE-1999-0091 GITHUB shell STUB
IBM AIX - Buffer Overflow in writesrv Command
Buffer overflow in AIX writesrv command allows local users to obtain root access.
CVE-1999-0094 GITHUB shell STUB
IBM AIX - Privilege Escalation via piodmgrsu Command
AIX piodmgrsu command allows local users to gain additional group privileges.
CVE-1999-0089 GITHUB shell STUB
IBM AIX - Buffer Overflow in libDtSvc Library
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
CVE-1999-0095 GITHUB shell STUB
Sendmail - Authenticated Remote Code Execution via Debug Command
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
CVE-1999-0019 GITHUB shell STUB
statd - Info Disclosure
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0022 GITHUB HIGH shell STUB
SGI IRIX - Local Privilege Escalation via rdist expstr() Buffer Overflow
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
CVSS 7.8
CVE-1999-0090 GITHUB shell STUB
IBM AIX - Buffer Overflow in rcp Command
Buffer overflow in AIX rcp command allows local users to obtain root access.
CVE-1999-0088 GITHUB shell STUB
IBM AIX - Unauthenticated Remote Code Execution via automountd Service
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
CVE-2025-13486 GITHUB CRITICAL shell STUB
Advanced Custom Fields: Extended <0.9.1.1 - RCE
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
CVSS 9.8
CVE-1999-0021 GITHUB shell STUB
wwwcount - Remote Command Execution via Buffer Overflow in Count.cgi
Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.
CVE-1999-0020 GITHUB shell STUB
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0092 GITHUB shell STUB
AIX Portmir - Privilege Escalation
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.
CVE-1999-0084 GITHUB HIGH shell STUB
Sun NFS - Improper Privilege Management via mknod Device Creation
Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.
CVSS 8.4
CVE-1999-0003 GITHUB shell STUB
Tritreal Ted Cde - Buffer Overflow
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
CVE-1999-0098 GITHUB shell STUB
AppleShare - Buffer Overflow via SMTP HELO Command
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
CVE-1999-0056 GITHUB shell STUB
SunOS - Buffer Overflow in Ping Program
Buffer overflow in Sun's ping program can give root access to local users.
CVE-1999-0025 GITHUB shell STUB
SGI IRIX - Buffer Overflow in df Command
root privileges via buffer overflow in df command on SGI IRIX systems.
CVE-1999-0016 GITHUB shell STUB
Cisco IOS - Denial of Service via Land IP Attack
Land IP denial of service.