HORKimhab

260 exploits Active since Oct 1988
CVE-1999-0068 GITHUB shell STUB
PHP - Unauthenticated Arbitrary File Read via CGI mylog Script
CGI PHP mylog script allows an attacker to read any file on the target server.
CVE-2025-6389 GITHUB CRITICAL shell SUSPICIOUS
Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution via sneeit_articles_pagination_callback
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible for unauthenticated attackers to execute code on the server which can be leveraged to inject backdoors or, for example, create new administrative user accounts.
CVSS 9.8
CVE-2026-46333 GITHUB HIGH shell WRITEUP
ptrace: slightly saner 'get_dumpable()' logic
In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - the concept comes from whether it can core dump or not - and makes no sense when you don't have an associated mm. And almost all users do in fact use it only for the case where the task has a mm pointer. But we have one odd special case: ptrace_may_access() uses 'dumpable' to check various other things entirely independently of the MM (typically explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for threads that no longer have a VM (and maybe never did, like most kernel threads). It's not what this flag was designed for, but it is what it is. The ptrace code does check that the uid/gid matches, so you do have to be uid-0 to see kernel thread details, but this means that the traditional "drop capabilities" model doesn't make any difference for this all. Make it all make a *bit* more sense by saying that if you don't have a MM pointer, we'll use a cached "last dumpability" flag if the thread ever had a MM (it will be zero for kernel threads since it is never set), and require a proper CAP_SYS_PTRACE capability to override.
CVSS 7.1
CVE-2016-3714 GITHUB HIGH shell STUB
ImageMagick <6.9.3-10 & <7.0.1-1 - RCE
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
CVSS 8.4
CVE-1999-0062 GITHUB shell STUB
OpenBSD - Local Privilege Escalation via File Descriptor Leakage in chpass
The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.
CVE-2024-9234 GITHUB CRITICAL shell SUSPICIOUS
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.
CVSS 9.8
CVE-1999-0063 GITHUB shell STUB
Cisco IOS - Denial of Service via Malicious UDP Syslog Packets
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
CVE-1999-0018 GITHUB shell STUB
SGI IRIX - Buffer Overflow in statd
Buffer overflow in statd allows root privileges.
CVE-1999-0100 GITHUB shell STUB
AIX innd 1.5.1 - Remote Access via Control Messages
Remote access in AIX innd 1.5.1, using control messages.
CVE-2025-12352 GITHUB CRITICAL shell STUB
Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via copy_post_image()
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post
CVSS 9.8
CVE-1999-0097 GITHUB shell STUB
HP-UX - Remote Command Execution via FTP Client Shell Metacharacter Injection
The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).
CVE-1999-0019 GITHUB shell STUB
statd - Info Disclosure
Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0098 GITHUB shell STUB
AppleShare - Buffer Overflow via SMTP HELO Command
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.
CVE-1999-0089 GITHUB shell STUB
IBM AIX - Buffer Overflow in libDtSvc Library
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
CVE-1999-0061 GITHUB shell STUB
BSD lpd - Unauthenticated Remote Command Execution
File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).
CVE-1999-0008 GITHUB shell STUB
HP-UX and Solaris - Buffer Overflow in NIS+ rpc.nisd
Buffer overflow in NIS+, in Sun's rpc.nisd program.
CVE-1999-0064 GITHUB shell STUB
IBM AIX - Buffer Overflow in lquerylv Program
Buffer overflow in AIX lquerylv program gives root access to local users.
CVE-1999-0099 GITHUB shell STUB
BSD/OS - Buffer Overflow in Syslog Utility
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVE-2025-13486 GITHUB CRITICAL shell STUB
Advanced Custom Fields: Extended <0.9.1.1 - RCE
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
CVSS 9.8
CVE-1999-0093 GITHUB shell STUB
AIX nslookup - Privilege Escalation
AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.
CVE-1999-0001 GITHUB shell SUSPICIOUS
BSD-derived TCP/IP Implementations - Denial of Service via Crafted Packets
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
CVE-1999-0002 GITHUB shell STUB
Bsdi Bsd OS - Memory Corruption
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
CVE-1999-0003 GITHUB shell STUB
Tritreal Ted Cde - Buffer Overflow
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
CVE-1999-0004 GITHUB shell STUB
HP dtmail - Buffer Overflow via MIME Processing
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
CVE-1999-0025 GITHUB shell STUB
SGI IRIX - Buffer Overflow in df Command
root privileges via buffer overflow in df command on SGI IRIX systems.