Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC
OpenSSH 用户名枚举漏洞(CVE-2018-15473)
CVE-2018-15473MEDIUM19 Jun 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RISK
open
GitHub PoC2
oldthree3/CVE-2019-12735-VIM-NEOVIM
CVE-2019-1273518 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC11
CVE-2019-2725 bypass pocscan and exp
CVE-2019-2725HIGHunder attackransomware16 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
MrAli-Code/CVE-2018-9995_dvr_credentials
CVE-2018-999516 Jun 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC1
CVE-2019-1064 - AppXSVC Local Privilege Escalation
CVE-2019-1064HIGHunder attackransomware16 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC35
weblogic绕过和wls远程执行
CVE-2019-2725HIGHunder attackransomware15 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1
Simple Bash shell quick fix CVE-2019-10149
CVE-2019-10149CRITICALunder attack14 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
蓝屏poc
CVE-2019-0708CRITICALunder attackransomware13 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 Jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RISK
open
GitHub PoC
改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏
CVE-2019-0708CRITICALunder attackransomware13 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 Jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RISK
open
GitHub PoC14
PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.
CVE-2019-10149CRITICALunder attack13 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC
CVE-2019-0708-RCE
CVE-2019-0708CRITICALunder attackransomware12 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708-Msf-验证
CVE-2019-0708CRITICALunder attackransomware12 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHunder attackransomware12 Jun 2019
Windows Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC7
LPE Exploit For CVE-2019-12181 (Serv-U FTP 15.1.6)
CVE-2019-1218112 Jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISK
open
GitHub PoC14
simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.
CVE-2019-10149CRITICALunder attack12 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC2
welove88888/CVE-2019-2725
CVE-2019-2725HIGHunder attackransomware11 Jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC58
A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.
CVE-2019-0841HIGHunder attackransomware11 Jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RISK
open
GitHub PoC13
CVE-2019-0708批量检测
CVE-2019-0708CRITICALunder attackransomware11 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC22
quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos
CVE-2019-10149CRITICALunder attack10 Jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RISK
open
GitHub PoC1
POC of CVE-2018-8718 + tool
CVE-2018-871810 Jun 2019
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RISK
open
GitHub PoC2
POC of CVE-2017-5487 + tool
CVE-2017-548710 Jun 2019
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RISK
open
GitHub PoC1
exploit tool of CVE-2018-10118
CVE-2018-1011810 Jun 2019
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RISK
open
GitHub PoC1
exploit tool of CVE-2018-11564
CVE-2018-1156410 Jun 2019
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RISK
open
GitHub PoC118
CVE-2019-0859 1day Exploit
CVE-2019-0859HIGHunder attack07 Jun 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RISK
open
GitHub PoC9
Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)
CVE-2019-1273506 Jun 2019
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RISK
open
GitHub PoC
799600966/CVE-2018-17456
CVE-2018-1745605 Jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RISK
open
GitHub PoC
loudong
CVE-2015-754704 Jun 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISK
open
previouspage 424 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.