Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Exploit-DBVexDay Proof
Shopware - createInstanceFromNamedArguments PHP Object Instantiation Remote Code Execution (Metasploit)
CVE-2017-18357remotephp23 May 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RISK
open
Exploit-DB
Microsoft Windows - AppX Deployment Service Local Privilege Escalation (2)
CVE-2019-0841HIGHunder attackransomwarelocalwindows23 May 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC3
cyy95/CVE-2019-0232-EXP
CVE-2019-023223 May 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RISK
open
GitHub PoC2
Working proof of concept for CVE-2019-0708, spawns remote shell.
CVE-2019-0708CRITICALunder attackransomware23 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Nagios XI 5.6.1 - SQL injection
CVE-2019-12279webappsphp23 May 2019
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). N
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OS X - Feedback Assistant Race Condition (Metasploit)
CVE-2019-8565localmacos23 May 2019
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RISK
open
Exploit-DBVexDay Proof
Visual Voicemail for iPhone - IMAP NAMESPACE Processing Use-After-Free
CVE-2019-8613dosios23 May 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, tvOS 12.3, watchO
28RISK
open
GitHub PoC3
CVE-2019-12460|Reflected XSS in WebPort-v1.19.1 impacts users who open a maliciously crafted link or third-party web page.
CVE-2019-1246023 May 2019
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RISK
open
GitHub PoC9
Exploit Generator for CVE-2018-8174 & CVE-2019-0768 (RCE via VBScript Execution in IE11)
CVE-2019-076823 May 2019
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RISK
open
Exploit-DB
Microsoft Windows (x86/x64) - 'Error Reporting' Discretionary Access Control List / Local Privilege Escalation
CVE-2019-0863HIGHunder attacklocalwindows22 May 2019
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Erro
71RISK
open
Metasploit600
Atlassian Crowd pdkinstall Unauthenticated Plugin Upload RCE
CVE-2019-11580CRITICALunder attackransomware22 May 2019
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RISK
open
GitHub PoC1
根据360Vulcan Team开发的CVE-2019-0708单个IP检测工具构造了个批量检测脚本而已
CVE-2019-0708CRITICALunder attackransomware22 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALunder attackransomware22 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
AUO Solar Data Recorder < 1.3.0 - 'addr' Cross-Site Scripting
CVE-2019-11368webappshardware22 May 2019
Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.
23RISK
open
Exploit-DB
Zoho ManageEngine ServiceDesk Plus < 10.5 - Improper Access Restrictions
CVE-2019-12252webappsmultiple22 May 2019
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post
23RISK
open
Exploit-DB
Carel pCOWeb < B1.2.1 - Cross-Site Scripting
CVE-2019-11370webappshardware22 May 2019
Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" f
38RISK
open
Exploit-DB
Carel pCOWeb < B1.2.1 - Credentials Disclosure
CVE-2019-11369webappshardware22 May 2019
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext pass
23RISK
open
GitHub PoC6
major203/cve-2019-0708-scan
CVE-2019-0708CRITICALunder attackransomware22 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC3
Scanner PoC for CVE-2019-0708 RDP RCE vuln
CVE-2019-0708CRITICALunder attackransomware22 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Zoho ManageEngine ServiceDesk Plus 9.3 - Cross-Site Scripting
CVE-2019-12189webappsmultiple22 May 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RISK
open
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALunder attack21 May 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RISK
open
GitHub PoC1
zjw88282740/CVE-2019-0708-win7
CVE-2019-0708CRITICALunder attackransomware21 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC4
My bot (badly written) to search and monitor cve-2019-0708 repositories
CVE-2019-0708CRITICALunder attackransomware21 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-1821HIGH21 May 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RISK
open
Exploit-DB
TP-LINK TL-WR840N v5 00000005 - Cross-Site Scripting
CVE-2019-12195webappshardware21 May 2019
TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - AIR Optimization Incorrectly Removes Assignment to Register
CVE-2019-8611dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 XNU - Wild-read due to bad cast in stf_ioctl
CVE-2019-8591dosmultiple21 May 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS Mojave 10.14.
23RISK
open
Exploit-DBVexDay Proof
Apple macOS < 10.14.5 / iOS < 12.3 JavaScriptCore - Loop-Invariant Code Motion (LICM) in DFG JIT Leaves Stack Variable Uninitialized
CVE-2019-8623dosmultiple21 May 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.3, macOS M
23RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9881webappsphp21 May 2019
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RISK
open
Exploit-DB
WordPress Plugin WPGraphQL 0.2.3 - Multiple Vulnerabilities
CVE-2019-9880webappsphp21 May 2019
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible,
50RISK
open
previouspage 834 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.