Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

76,006cataloged exploits
34,638CVEs with public exploitation
24,695lab-tested
13,727 exploits
GitHub PoC1
Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC6
Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
winrar exploit 6.22 <=
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC13
This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
winrar exploit 6.22 <=
CVE-2023-38831HIGHunder attackransomware30 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
CVE-2023-27524
CVE-2023-27524HIGHunder attack30 Aug 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISK
open
GitHub PoC24
PoC Script for CVE-2023-4596, unauthenticated Remote Command Execution through arbitrary file uploads.
CVE-2023-4596CRITICAL30 Aug 2023
Forminator <= 1.24.6 - Unauthenticated Arbitrary File Upload
68RISK
open
GitHub PoC
hanmin0512/CVE-2014-6271_pwnable
CVE-2014-6271CRITICALunder attack29 Aug 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open
GitHub PoC5
Remote Code Execution on Junos OS CVE-2023-36846
CVE-2023-36846MEDIUMunder attack29 Aug 2023
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
85RISK
open
GitHub PoC1
Proof of Concept (POC) for CVE-2023-38831 WinRAR
CVE-2023-38831HIGHunder attackransomware29 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.
CVE-2023-38831HIGHunder attackransomware29 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC13
Adapted CVE-2020-0041 root exploit for Pixel 3
CVE-2020-0041HIGHunder attack29 Aug 2023
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RISK
open
GitHub PoC22
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC3
CVE-2023-38831 WinRAR
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC40
Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC90
CVE-2023-38831 PoC (Proof Of Concept)
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC4
KQL Hunting for WinRAR CVE-2023-38831
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC11
CVE-2023-38831 winrar exploit generator and get reverse shell
CVE-2023-38831HIGHunder attackransomware28 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC
CVE-2023-28432检测工具
CVE-2023-28432HIGHunder attack28 Aug 2023
Minio Information Disclosure in Cluster Deployment
100RISK
open
GitHub PoC6
CloudPanel 2 Remote Code Execution Exploit
CVE-2023-35885CRITICAL28 Aug 2023
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
85RISK
open
GitHub PoC7
PHPUnit RCE
CVE-2017-9841CRITICALunder attack27 Aug 2023
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RISK
open
GitHub PoC114
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
CVE-2023-38831HIGHunder attackransomware27 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC128
一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。
CVE-2023-38831HIGHunder attackransomware27 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC2
IR-HuntGuardians/CVE-2023-38831-HUNT
CVE-2023-38831HIGHunder attackransomware27 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
GitHub PoC1
POC for CVE-2023-24489 with bash.
CVE-2023-24489CRITICALunder attack27 Aug 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RISK
open
GitHub PoC1
Python implementation of CVE-2018-16858
CVE-2018-16858HIGH26 Aug 2023
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RISK
open
GitHub PoC
krmxd/CVE-2023-2868
CVE-2023-2868CRITICALunder attack25 Aug 2023
Remote Code injection in Barracuda Email Security Gateway
100RISK
open
GitHub PoC115
watchtowrlabs/juniper-rce_cve-2023-36844
CVE-2023-36844MEDIUMunder attack25 Aug 2023
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
100RISK
open
GitHub PoC7
A PoC exploit for CVE-2021-42013 - Apache 2.4.49 & 2.4.50 Remote Code Execution
CVE-2021-42013CRITICALunder attackransomware25 Aug 2023
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open
GitHub PoC785
CVE-2023-38831 winrar exploit generator
CVE-2023-38831HIGHunder attackransomware25 Aug 2023
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a
100RISK
open
previouspage 261 / 458next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.