Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,697cataloged exploits
36,715CVEs with public exploitation
24,695lab-tested
79,305 exploits
GitHub PoC
tarantula-team/CVE-2019-12541
CVE-2019-1254104 Jun 2019
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText par
23RISK
open
Metasploit300
Supra Smart Cloud TV Remote File Inclusion
CVE-2019-1247703 Jun 2019
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RISK
open
GitHub PoC37
Privesc through import of Sheduled tasks + Hardlinks - CVE-2019-1069
CVE-2019-1069HIGHunder attackransomware03 Jun 2019
Task Scheduler Elevation of Privilege Vulnerability
71RISK
open
Exploit-DB
WordPress Plugin Form Maker 1.13.3 - SQL Injection
CVE-2019-10866webappsphp03 Jun 2019
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_
23RISK
open
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5405webappsphp03 Jun 2019
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RISK
open
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5404webappsphp03 Jun 2019
The Quest Kace K1000 Appliance is vulnerable to multiple Blind SQL Injections.
23RISK
open
GitHub PoC27
Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support
CVE-2019-0708CRITICALunder attackransomware03 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5406webappsphp03 Jun 2019
The Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
28RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware03 Jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2017-0144HIGHunder attackransomware02 Jun 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
GitHub PoC1
CVE-2017-0144
CVE-2017-0144HIGHunder attackransomware02 Jun 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RISK
open
Metasploit600
Ahsay Backup v7.x-v8.1.1.50 (authenticated) file upload
CVE-2019-1026701 Jun 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RISK
open
GitHub PoC1
CVE-2019-0708批量蓝屏恶搞
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
JasonLOU/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC40
CVE-2019-0708 - BlueKeep (RDP)
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC342
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALunder attackransomware31 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1
CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DB
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service
CVE-2019-0708CRITICALunder attackransomwaredoswindows30 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
Exploit-DBVexDay Proof
Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL
CVE-2019-10529dosandroid29 May 2019
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
23RISK
open
GitHub PoC433
CVE-2019-2725 命令回显
CVE-2019-2725HIGHunder attackransomware29 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Leaks JS_OPTIMIZED_OUT Magic Value to Script
CVE-2019-9792dosmultiple29 May 2019
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during
28RISK
open
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC1,183
Proof of concept for CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
VulnCheck XDB
initial-access
CVE-2019-2725HIGHunder attackransomware29 May 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RISK
open
GitHub PoC
CVE-2019-0708 bluekeep 漏洞检测
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
GitHub PoC6
infiniti-team/CVE-2019-0708
CVE-2019-0708CRITICALunder attackransomware29 May 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISK
open
previouspage 832 / 2,644next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.