VulnSea

Tagged “exploit-available”

CVEs tagged exploit-available, newest first.

3860 CVEsRSS

CVE-1999-1491High· 7.2PoC
30y ago

abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

▾ MidnightEPSS 1.9%via NVD
CVE-1999-0208Critical· 10.0PoC
30y ago

rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

▾ AbyssalEPSS 13%via NVD
CVE-1999-0066Critical· 9.8PoC
31y ago

AnyForm CGI remote execution.

AnyForm CGI remote execution.

▾ AbyssalEPSS 12%via NVD
CVE-1999-1243Medium· 4.6PoC
31y ago

SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.

SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.

▾ TwilightEPSS 0.61%via NVD
CVE-1999-0235Critical· 10.0PoC
31y ago

Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.

Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.

▾ AbyssalEPSS 6.6%via NVD
CVE-1999-0077Medium· 5.0PoC
31y ago

Predictable TCP sequence numbers allow spoofing.

Predictable TCP sequence numbers allow spoofing.

▾ TwilightEPSS 31%via NVD
CVE-2000-0508Medium· 5.0PoC
31y ago

rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.

rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.

▾ TwilightEPSS 8.6%via NVD
CVE-1999-1022Medium· 6.2PoC
32y ago

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

▾ TwilightEPSS 0.79%via NVD
CVE-1999-1219High· 7.2PoC
32y ago

Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.

Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.

▾ MidnightEPSS 1.3%via NVD
CVE-1999-1494Low· 2.1PoC
32y ago

colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.

colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.

▾ TwilightEPSS 0.95%via NVD
CVE-1999-0207High· 7.5PoC
32y ago

Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.

Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.

▾ MidnightEPSS 8.7%via NVD
CVE-1999-0113Critical· 10.0PoC
32y ago

Some implementations of rlogin allow root access if given a -froot parameter.

Some implementations of rlogin allow root access if given a -froot parameter.

▾ AbyssalEPSS 17%via NVD
CVE-1999-1123High· 7.2PoC
35y ago

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

▾ MidnightEPSS 1.1%via NVD
CVE-1999-1194High· 7.2PoC
35y ago

chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

▾ MidnightEPSS 0.96%via NVD
CVE-1999-0209Medium· 5.0PoC
36y ago

The SunView (SunTools) selection_svc facility allows remote users to read files.

The SunView (SunTools) selection_svc facility allows remote users to read files.

▾ TwilightEPSS 49%via NVD
CVE-1999-0095Critical· 10.0PoC
38y ago

The debug command in Sendmail is enabled, allowing attackers to execute commands as root.

The debug command in Sendmail is enabled, allowing attackers to execute commands as root.

▾ AbyssalEPSS 16%via NVD
CVE-2025-31200High· 7.5CISA KEV0dayPoC

Memory corruption in CoreAudio via crafted media file

A maliciously crafted media file processed by Apple CoreAudio can trigger heap corruption leading to remote code execution. Reported as exploited in the wild against targeted individuals.

▾ AbyssalApple · CoreAudioiOS, iPadOS, macOSEPSS 19%via NVD
CVE-2025-29927Critical· 9.1PoC

Next.js middleware authorization bypass via x-middleware-subrequest

A crafted x-middleware-subrequest header lets an attacker skip Next.js middleware execution entirely, bypassing authentication/authorization checks implemented in middleware.

▾ AbyssalNext.js · Next.jsNode.js, WebEPSS 99%via GHSA
CVE-2024-3094Critical· 10.0PoC

Malicious backdoor in xz/liblzma (supply-chain compromise)

A backdoor was intentionally introduced into the xz-utils upstream release tarballs (5.6.0 / 5.6.1). When linked into sshd via liblzma, it allows a remote attacker holding a specific key to bypass authentication and execute commands.

▾ Abyssalliblzma · liblzmaLinuxEPSS 86%via GHSA
CVE-2021-44228Critical· 10.0CISA KEV0dayPoC

Log4Shell: JNDI RCE in Apache Log4j 2

Log4j 2 evaluates ${jndi:...} lookups in logged strings, allowing an attacker who controls any logged value to load and execute remote code via LDAP/RMI. Trivial to exploit, ubiquitous, and mass-exploited within hours of disclosure.

▾ HadalApache · Log4j 2JavaEPSS 100%via NVD
CVEs tagged “exploit-available” — page 129 · VulnSea