Vulnerabilities Exploited in the Wild with Public PoC
Updated 2h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
2,390 results
Clear all
CVE-2001-0236
EXPLOITED
2 PoCs
Analysis
EPSS 0.70
SUN Solaris - Buffer Overflow
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long "indication" event.
May 03, 2001
CVE-2001-0500
EXPLOITED
6 PoCs
Analysis
EPSS 0.91
Microsoft Index Server < 6.0 - Buffer Overflow
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.
Jul 21, 2001
CVE-2000-0984
EXPLOITED
1 PoC
Analysis
EPSS 0.40
Cisco IOS <12.2 - DoS
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.
Dec 19, 2000
CVE-2000-0325
EXPLOITED
1 PoC
Analysis
EPSS 0.07
Microsoft Jet - Command Injection
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
Aug 20, 1999
CVE-2000-0248
EXPLOITED
3 PoCs
Analysis
EPSS 0.76
Red Hat Linux Piranha - Command Injection
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
Apr 24, 2000
CVE-2000-0322
EXPLOITED
1 PoC
Analysis
EPSS 0.78
Red Hat Piranha - Command Injection
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.
Apr 24, 2000
CVE-2000-0884
EXPLOITED
9 PoCs
Analysis
EPSS 0.84
IIS 4.0-5.0 - Path Traversal
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.
Dec 19, 2000
CVE-1999-0526
EXPLOITED
3 PoCs
Analysis
EPSS 0.73
X Server - Info Disclosure
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
Jul 01, 1997
CVE-1999-0192
EXPLOITED
2 PoCs
Analysis
EPSS 0.07
Redhat Linux - Buffer Overflow
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
Oct 18, 1997
CVE-1999-0502
EXPLOITED
23 PoCs
Analysis
EPSS 0.37
Unix - Info Disclosure
A Unix account has a default, null, blank, or missing password.
Mar 01, 1998