Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,058cataloged exploits
35,300CVEs with public exploitation
24,695lab-tested
14,080 exploits
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12543
CVE-2019-1254304 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceReques
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12538
CVE-2019-1253804 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
23RISK
open
GitHub PoC
tarantula-team/CVE-2019-12542
CVE-2019-1254204 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID paramete
23RISK
open
GitHub PoC37
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
CVE-2019-1069HIGHunder attackransomware03 Jun 2019
Task Scheduler Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC27
Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support
CVE-2019-0708CRITICALunder attackransomware03 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware02 Jun 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC342
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
JasonLOU/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708批量蓝屏恶搞
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC40
CVE-2019-0708 - BlueKeep (RDP)
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
CVE-2019-0708 bluekeep 漏洞检测
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC433
CVE-2019-2725 命令回显
CVE-2019-2725HIGHunder attackransomware29 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC1,181
Proof of concept for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC6
infiniti-team/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
haishanzheng/CVE-2019-0708-generate-hosts
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC5
基于360公开的无损检测工具的可直接在windows上运行的批量检测程序
CVE-2019-0708CRITICALunder attackransomware28 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
ABIZCHI/CVE-2018-9995_dvr_credentials
CVE-2018-999528 May 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISK
open
GitHub PoC127
Only Hitting PoC [Tested on Windows Server 2008 r2]
CVE-2019-0708CRITICALunder attackransomware28 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC2
aenlr/strutt-cve-2014-0114
CVE-2014-011427 May 2019
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISK
open
GitHub PoC71
Drupal8's REST RCE, SA-CORE-2019-003, CVE-2019-6340
CVE-2019-6340HIGHunder attack27 May 2019
Drupal core - Highly critical - Remote Code Execution
100RISK
open
GitHub PoC
Arbitrary deserialization that can be used to trigger SQL injection and even Code execution
CVE-2013-015627 May 2019
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISK
open
GitHub PoC
caxmd/CVE-2017-13156
CVE-2017-1315627 May 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RISK
open
GitHub PoC6
Mass MikroTik WinBox Exploitation tool, CVE-2018-14847
CVE-2018-14847CRITICALunder attack26 May 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISK
open
GitHub PoC
50 first stargazers will get get the tool via email
CVE-2019-0708CRITICALunder attackransomware24 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC13
cve-2019-0708 poc .
CVE-2019-0708CRITICALunder attackransomware24 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC
yehnah
CVE-2017-8759HIGHunder attack24 May 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RISK
open
GitHub PoC9
Exploit Generator for CVE-2018-8174 & CVE-2019-0768 (RCE via VBScript Execution in IE11)
CVE-2019-076823 May 2019
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
28RISK
open
previouspage 425 / 470next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.