Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
29New in 24h
356PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11105 results

CVE-2026-24046
NEWHIGHFRESH PoC
CVSS 7.1 HIGH CWE-22, CWE-59 Published 2026-01-21 PoCs 1 ★ 0 Last push 2026-10-09 (13 hours, 38 minutes ago) Discovered 2026-10-09 14:08

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Show 1 repositories
Rem1L/cve-2026-24046-poc
★ 0 · 2026-10-09
CVE-2024-36774
NEWHIGHFRESH PoC
CVSS 7.2 HIGH CWE-434 Published 2024-06-06 PoCs 1 ★ 0 Last push 2026-10-09 (14 hours, 39 minutes ago) Discovered 2026-10-09 14:08

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Show 1 repositories
CVE-2026-28775
NEWCRITICALFRESH PoC
CVSS 10.0 CRITICAL CWE-1188 Published 2026-03-04 PoCs 1 ★ 0 Last push 2026-10-09 (15 hours, 14 minutes ago) Discovered 2026-10-09 14:08

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Show 1 repositories
Udyz/CVE-2026-28775

CVE-2026-28775 SNMP RCE

★ 0 · 2026-10-09
CVE-2026-107406
NEWCRITICALFRESH PoC
CVSS 9.5 CRITICAL CWE-119 Published 2026-10-08 PoCs 2 ★ 0 Last push 2026-10-09 (17 hours, 34 minutes ago) Discovered 2026-10-09 14:08

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Show 2 repositories
techupdate24/citrix-netscaler-rce-cve-2026-107406

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-09
ApexBreach/CVE-2026-107406-Poc
★ 0 · 2026-10-09
CVE-2022-21812
NEWHIGHFRESH PoC
CVSS 7.8 HIGH Published 2022-08-18 PoCs 1 ★ 0 Last push 2026-10-09 (18 hours, 24 minutes ago) Discovered 2026-10-09 14:08

Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Show 1 repositories
CVE-2016-10134
NEWCRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-89 Published 2017-02-17 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 34 minutes ago) Discovered 2026-10-09 03:16

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

Show 1 repositories
CyberCTF/vulhub-zabbix-cve-2016-10134

Vulhub zabbix/CVE-2016-10134: Zabbix latest.php and jsrpc.php SQL Injection (CVE-2016-10134), run with Isoloom

★ 0 · 2026-10-09
CVE-2017-14849
NEWHIGHFRESH PoC
CVSS 7.5 HIGH CWE-22 Published 2017-09-28 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 37 minutes ago) Discovered 2026-10-09 03:16

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

Show 1 repositories
CyberCTF/vulhub-node-cve-2017-14849

Vulhub node/CVE-2017-14849: Node.js 8.5.0 Path Traversal (CVE-2017-14849), run with Isoloom

★ 0 · 2026-10-09
CVE-2018-8715
NEWHIGHFRESH PoC
CVSS 8.1 HIGH CWE-287 Published 2018-03-15 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 40 minutes ago) Discovered 2026-10-09 03:16

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Show 1 repositories
CyberCTF/vulhub-appweb-cve-2018-8715

Vulhub appweb/CVE-2018-8715: Appweb Digest Authentication Bypass (CVE-2018-8715), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-39214
NEWHIGHFRESH PoC
CVSS 8.1 HIGH CWE-444 Published 2021-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 44 minutes ago) Discovered 2026-10-09 03:16

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.

Show 1 repositories
CyberCTF/secdevlabs-golden-hat

secDevLabs Golden Hat Society: mitmproxy 5.3.0 request smuggling, CVE-2021-39214 (OWASP A06), run with Isoloom

★ 0 · 2026-10-09
CVE-2026-95149
NEWFRESH PoC
PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 55 minutes ago) Discovered 2026-10-09 14:08

Fetching description from NVD…

Show 1 repositories
reputati0n/CVE-2026-95149
★ 0 · 2026-10-09
CVE-2025-41249
NEWHIGHFRESH PoC
CVSS 7.5 HIGH CWE-285 Published 2025-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 46 minutes ago) Discovered 2026-10-09 14:08

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .

Show 1 repositories
edwin/simulating-cve-2025-41249
★ 0 · 2026-10-09
CVE-2021-30535
NEWHIGHFRESH PoC
CVSS 8.8 HIGH CWE-415 Published 2021-06-07 PoCs 1 ★ 0 Last push 2026-10-09 (21 hours, 25 minutes ago) Discovered 2026-10-09 03:16

Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Show 1 repositories
califio/icu4x-crubit-demo

C++ contact-list demo comparing vulnerable ICU4C 66.1 with ICU4X through Crubit (CVE-2021-30535).

★ 0 · 2026-10-09
CVE-2026-94597
NEWFRESH PoC
PoCs 1 ★ 0 Last push 2026-10-09 (22 hours, 19 minutes ago) Discovered 2026-10-09 14:08

Fetching description from NVD…

Show 1 repositories
canhieu/CVE-2026-94597-poc

CVE-2026-94597

★ 0 · 2026-10-09
CVE-2026-55450
NEWCRITICALFRESH PoC
CVSS 9.3 CRITICAL CWE-200, CWE-306, CWE-400 Published 2026-06-23 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 3 hours ago) Discovered 2026-10-09 03:16

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.

Show 1 repositories
0xBlackash/CVE-2026-55450

CVE-2026-55450

★ 0 · 2026-10-08
CVE-2026-91940
NEWHIGHFRESH PoC
CVSS 8.7 HIGH CWE-22 Published 2026-09-15 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 5 hours ago) Discovered 2026-10-09 03:16

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.

Show 1 repositories
BiiTts/CVE-2026-91940-crawl4ai-Arbitrary-File-Write

CVE-2026-91940: arbitrary file write in crawl4ai <=0.9.2 via the untrusted-config gate (PDFContentScrapingStrategy image_save_dir). Analysis, reproduction harn…

★ 0 · 2026-10-08
CVE-2026-92555
NEWCRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-201 Published 2026-10-08 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 6 hours ago) Discovered 2026-10-09 03:16

Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26.

Show 1 repositories
Enay-Project/CVE-2026-92555

CVE-2026-92555 Exploit

★ 0 · 2026-10-08
CVE-2026-106610
NEWFRESH PoC
PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 7 hours ago) Discovered 2026-10-09 03:16

Fetching description from NVD…

Show 1 repositories
KevineCharles/CVE-2026-106610-miniorange-otp-ato

PoC: miniOrange OTP Verification <=5.5.7 unauthenticated Account Takeover via OTP re-routing (CVSS 9.8)

★ 0 · 2026-10-08
CVE-2020-25134
NEWHIGH
CVSS 8.8 HIGH CWE-22, CWE-434 Published 2020-09-25 PoCs 1 ★ 0 Last push 2021-07-13 (5 years, 2 months ago) Discovered 2026-10-09 03:16

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /settings/?format=../ URIs to pages/settings.inc.php.

Show 1 repositories
ynsmroztas/CVE-2020-25134

CVE-2020-25134 Authenticated Local File Inclusion in settings/format

★ 0 · 2021-07-13
CVE-2020-0887
NEWHIGH
CVSS 7.8 HIGH Published 2020-03-12 PoCs 1 ★ 0 Last push 2021-07-12 (5 years, 2 months ago) Discovered 2026-10-09 03:16

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.

Show 1 repositories
vinhthp1712/CVE-2020-0887
★ 0 · 2021-07-12
CVE-2020-24148
NEWCRITICAL
CVSS 9.1 CRITICAL CWE-918 Published 2021-07-07 PoCs 1 ★ 5 Last push 2021-07-12 (5 years, 2 months ago) Discovered 2026-10-09 03:16

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

Show 1 repositories
dwisiswant0/CVE-2020-24148

CVE-2020-24148 Proof-of-Concept

★ 5 · 2021-07-12
CVE-2020-1956
NEWHIGH
CVSS 8.8 HIGH CWE-78 Published 2020-05-22 PoCs 1 ★ 0 Last push 2021-07-09 (5 years, 3 months ago) Discovered 2026-10-09 03:16

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Show 1 repositories
b510/CVE-2020-1956

CVE-2020-1956

★ 0 · 2021-07-09
CVE-2020-7115
NEWCRITICAL
CVSS 9.8 CRITICAL CWE-306 Published 2020-06-03 PoCs 1 ★ 1 Last push 2021-07-03 (5 years, 3 months ago) Discovered 2026-10-09 03:16

The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

Show 1 repositories
Retr02332/CVE-2020-7115

Create your malicious engine in seconds

★ 1 · 2021-07-03
CVSS 6.1 MEDIUM CWE-79 Published 2020-12-09 PoCs 1 ★ 3 Last push 2021-06-18 (5 years, 3 months ago) Discovered 2026-10-09 03:16

The moodlenetprofile user profile field required extra sanitizing to prevent a stored XSS risk. This affects versions 3.9 to 3.9.1. Fixed in 3.9.2.

Show 1 repositories
HoangKien1020/CVE-2020-25627

Stored XSS via moodlenetprofile parameter in user profile

★ 3 · 2021-06-18
CVSS 6.5 MEDIUM CWE-284 Published 2021-06-16 PoCs 1 ★ 1 Last push 2021-06-17 (5 years, 3 months ago) Discovered 2026-10-09 03:16

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a SAML SP or a SAML IdP for this to be possible.

Show 1 repositories
stuartcarroll/CitrixADC-CVE-2020-8300

Detect Citrix ADC SAML action or SAML iDP Profile config vulnerable to CVE-2020-8300 using Citrix ADC NITRO API

★ 1 · 2021-06-17
CVE-2020-13957
NEWCRITICAL
CVSS 9.8 CRITICAL CWE-863 Published 2020-10-13 PoCs 1 ★ 1 Last push 2021-06-06 (5 years, 4 months ago) Discovered 2026-10-09 03:16

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

Show 1 repositories
s-index/CVE-2020-13957

Apache Solr RCE CVE-2020-13957

★ 1 · 2021-06-06
Page 1 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.