Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,607cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
13,974 exploits
GitHub PoC12
ze0r/CVE-2019-0708-exp
CVE-2019-0708CRITICALunder attackransomware04 Jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
https://github.com/Yt1g3r/CVE-2019-3396_EXP.git
CVE-2019-3396CRITICALunder attackransomware01 Jul 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RISK
open
GitHub PoC
Proof of concept code for breaking out of docker via runC
CVE-2019-573630 Jun 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RISK
open
GitHub PoC3
TrungNguyen1909/CVE-2019-6225-macOS
CVE-2019-622530 Jun 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RISK
open
GitHub PoC9
CVE-2019-10149 privilege escalation
CVE-2019-10149CRITICALunder attack27 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
spectre v4 : Speculative Store Bypass (CVE-2018-3639) proof of concept for Linux
CVE-2018-3639MEDIUM26 Jun 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
GitHub PoC99
cve-2019-0604 SharePoint RCE exploit
CVE-2019-0604CRITICALunder attackransomware26 Jun 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RISK
open
GitHub PoC
CVE-2017-8759 微软word漏洞利用脚本
CVE-2017-8759HIGHunder attack25 Jun 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC14
POC CVE-2019-0708 with python script!
CVE-2019-0708CRITICALunder attackransomware24 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC70
Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行
CVE-2019-2725HIGHunder attackransomware24 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC
Spins up an isolated test environment for experimentation with Apache Struts vulnerability CVE-2018-11776.
CVE-2018-11776HIGHunder attack24 Jun 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISK
open
GitHub PoC9
CVE-2015-3337 ElasticSearch 任意文件读取
CVE-2015-333721 Jun 2019
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a
50RISK
open
GitHub PoC5
CVE-2018-17456漏洞复现(PoC+Exp)
CVE-2018-1745621 Jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC3
CVE-2017-1000117漏洞复现(PoC+Exp)
CVE-2017-100011720 Jun 2019
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RISK
open
GitHub PoC1
wdfcc/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware20 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
OpenSSH 用户名枚举漏洞(CVE-2018-15473)
CVE-2018-15473MEDIUM19 Jun 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC2
oldthree3/CVE-2019-12735-VIM-NEOVIM
CVE-2019-1273518 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC1
MrAli-Code/CVE-2018-9995_dvr_credentials
CVE-2018-999516 Jun 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC1
CVE-2019-1064 - AppXSVC Local Privilege Escalation
CVE-2019-1064HIGHunder attackransomware16 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC11
CVE-2019-2725 bypass pocscan and exp
CVE-2019-2725HIGHunder attackransomware16 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC35
weblogic绕过和wls远程执行
CVE-2019-2725HIGHunder attackransomware15 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
Simple Bash shell quick fix CVE-2019-10149
CVE-2019-10149CRITICALunder attack14 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 Jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RISK
open
GitHub PoC
蓝屏poc
CVE-2019-0708CRITICALunder attackransomware13 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏
CVE-2019-0708CRITICALunder attackransomware13 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC14
PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.
CVE-2019-10149CRITICALunder attack13 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC7
LPE Exploit For CVE-2019-12181 (Serv-U FTP 15.1.6)
CVE-2019-1218112 Jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
CVE-2019-0708-Msf-验证
CVE-2019-0708CRITICALunder attackransomware12 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
previouspage 420 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.