Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,610cataloged exploits
34,986CVEs with public exploitation
24,695lab-tested
13,974 exploits
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC58
A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.
CVE-2019-0841HIGHunder attackransomware11 Jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC13
CVE-2019-0708批量检测
CVE-2019-0708CRITICALunder attackransomware11 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
welove88888/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware11 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC22
quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos
CVE-2019-10149CRITICALunder attack10 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
POC of CVE-2017-5487 + tool
CVE-2017-548710 Jun 2019
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC1
exploit tool of CVE-2018-10118
CVE-2018-1011810 Jun 2019
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISK
open
GitHub PoC1
exploit tool of CVE-2018-11564
CVE-2018-1156410 Jun 2019
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISK
open
GitHub PoC1
POC of CVE-2018-8718 + tool
CVE-2018-871810 Jun 2019
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISK
open
GitHub PoC118
CVE-2019-0859 1day Exploit
CVE-2019-0859HIGHunder attack07 Jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
GitHub PoC9
Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)
CVE-2019-1273506 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC
799600966/CVE-2018-17456
CVE-2018-1745605 Jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC
tarantula-team/CVE-2019-12542
CVE-2019-1254204 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RISK
open
GitHub PoC
loudong
CVE-2015-754704 Jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
GitHub PoC
tarantula-team/CVE-2019-12538
CVE-2019-1253804 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12543
CVE-2019-1254304 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceReques
23RISK
open
GitHub PoC27
Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support
CVE-2019-0708CRITICALunder attackransomware03 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC37
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
CVE-2019-1069HIGHunder attackransomware03 Jun 2019
Task Scheduler Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware02 Jun 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC342
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
JasonLOU/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708批量蓝屏恶搞
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC40
CVE-2019-0708 - BlueKeep (RDP)
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1,181
Proof of concept for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC6
infiniti-team/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2019-0708 bluekeep 漏洞检测
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
previouspage 421 / 466next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.