Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,305cataloged exploits
36,465CVEs with public exploitation
24,695lab-tested
79,305 exploits
Metasploit600
DLINK DWL-2600 Authenticated Remote Command Injection
CVE-2019-2049915 May 2019
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RISK
open
GitHub PoC1
gildaaa/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
POCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC11
Totally legitimate
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
infenet/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC19
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC7
sup pry0cc :3
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC6
PoC exploit for BlueKeep (CVE-2019-0708)
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
exploit CVE-2019-0708 RDS
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC3
Testing my new bot out
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC3
Proof of concept exploit for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
Dark Net Sunset New Release CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC9
CVE-2019-0708 exp
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC31
Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC121
CVE-2019-0708-exploit
CVE-2019-0708CRITICALunder attackransomware15 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC47
proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection
CVE-2018-7841CRITICALunder attackwebappsphp14 May 2019
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code
100RISK
open
GitHub PoC13
A Win7 RDP exploit
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
peterpeter228/CNTA-2019-0014xCVE-2019-2725
CVE-2019-2725HIGHunder attackransomware14 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Metasploit0
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Metasploit300
CVE-2019-0708 BlueKeep Microsoft Remote Desktop RCE Check
CVE-2019-0708CRITICALunder attackransomware14 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
OpenProject 5.0.0 - 8.3.1 - SQL Injection
CVE-2019-11600webappsphp13 May 2019
A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi
45RISK
open
VulnCheck XDB
local
CVE-2019-0211HIGHunder attack12 May 2019
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
GitHub PoC11
CVE-2019-0211-apache & CVE-2019-6977-imagecolormatch
CVE-2019-0211HIGHunder attack12 May 2019
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RISK
open
VulnCheck XDB
remote-with-credentials
CVE-2018-3639MEDIUM11 May 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
GitHub PoC15
Speculative Store Bypass (CVE-2018-3639) proof of concept for Linux
CVE-2018-3639MEDIUM11 May 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RISK
open
GitHub PoC7
zhusx110/cve-2019-2725
CVE-2019-2725HIGHunder attackransomware10 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DB
CyberArk Enterprise Password Vault 10.7 - XML External Entity Injection
CVE-2019-7442webappsmultiple10 May 2019
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault
35RISK
open
Exploit-DBVexDay Proof
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
CVE-2019-7652webappsmultiple10 May 2019
TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the
23RISK
open
previouspage 837 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.