Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,449cataloged exploits
35,552CVEs with public exploitation
24,695lab-tested
77,302 exploits
VulnCheck XDB
initial-access
CVE-2023-41265CRITICALunder attackransomware30 Aug 2023
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and ear
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-3836MEDIUM30 Aug 2023
Dahua Smart Park Management unrestricted upload
70RISK
open
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALunder attack30 Aug 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
winrar exploit 6.22 <=
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC13
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-27524HIGHunder attack30 Aug 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC1
Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-35078CRITICALunder attackransomware30 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
GitHub PoC6
Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2023-26255HIGH30 Aug 2023
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-4596CRITICAL30 Aug 2023
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
VulnCheck XDB
initial-access
CVE-2023-41266HIGHunder attackransomware30 Aug 2023
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, Feb
100RISK
open
GitHub PoC
Ivanti Endpoint Manager Mobile (EPMM) POC
CVE-2023-35078CRITICALunder attackransomware30 Aug 2023
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or re
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC24
PoC Script for CVE-2023-4596, unauthenticated Remote Command Execution through arbitrary file uploads.
CVE-2023-4596CRITICAL30 Aug 2023
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
CVE-2022-46169
CVE-2022-46169CRITICALunder attack30 Aug 2023
Unauthenticated Command Injection
100RISK
open
GitHub PoC
CVE-2023-27524
CVE-2023-27524HIGHunder attack30 Aug 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
VulnCheck XDB
client-side
CVE-2023-38831HIGHunder attackransomware29 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
VulnCheck XDB
infoleak
CVE-2024-27564MEDIUM29 Aug 2023
pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references sec
60RISK
open
GitHub PoC
hanmin0512/CVE-2014-6271_pwnable
CVE-2014-6271CRITICALunder attack29 Aug 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
VulnCheck XDB
initial-access
CVE-2023-36846MEDIUMunder attack29 Aug 2023
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RISK
open
Metasploit600
VMWare Aria Operations for Networks (vRealize Network Insight) SSH Private Key Exposure
CVE-2023-34039CRITICAL29 Aug 2023
Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key g
75RISK
open
GitHub PoC
This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.
CVE-2023-38831HIGHunder attackransomware29 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC13
Adapted CVE-2020-0041 root exploit for Pixel 3
CVE-2020-0041HIGHunder attack29 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC1
Proof of Concept (POC) for CVE-2023-38831 WinRAR
CVE-2023-38831HIGHunder attackransomware29 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC5
Remote Code Execution on Junos OS CVE-2023-36846
CVE-2023-36846MEDIUMunder attack29 Aug 2023
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RISK
open
VulnCheck XDB
initial-access
CVE-2023-27163MEDIUM29 Aug 2023
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baske
48RISK
open
GitHub PoC22
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC11
CVE-2023-38831 winrar exploit generator and get reverse shell
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
previouspage 470 / 2,577next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.