Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

351 results

CVE-2026-64560
FRESH PoCMULTI PoC
PoCs 10 ★ 73 Last push 2026-10-09 (15 hours, 34 minutes ago)

Fetching description from NVD…

Show 8 of 10 repositories
quyicheng03-boop/xiaomi15-dada-cve-2026-64560

Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8

★ 21 · 2026-09-05
a23bc/op13-cve-2026-64560
★ 11 · 2026-09-27
qingle009/opace6-cve-2026-64560

OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

★ 7 · 2026-09-29
imkidz0/CVE-2026-64560-exploit

Exploit of CVE-2026-64560 for kernelCTF, LTS-6.12.95

★ 2 · 2026-10-03
Become-ILLUSORY/cve-2026-64560-a16

CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port

★ 1 · 2026-09-26
Wangs-official/opace6-cve-2026-64560

针对 OnePlus Ace6 设备的 cve-2026-64560 复现

★ 1 · 2026-09-25
CVE-2025-68921
FRESH PoC
PoCs 4 ★ 62 Last push 2026-10-09 (15 hours, 49 minutes ago)

Fetching description from NVD…

Show 4 repositories
ZeroMemoryEx/CVE-2025-68921

Local Privilege Escalation Affecting Millions of Gaming Laptops

★ 62 · 2026-01-19
kikiuuw/CVE-2025-68921

🔍 Identify and understand the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software, impacting many gaming laptops.

★ 0 · 2026-10-09
kikiuuw/kikiuuw.github.io

🔍 Explore the CVE-2025-68921 vulnerability in Nahimic, enabling local privilege escalation to `NT AUTHORITY\SYSTEM`.

★ 0 · 2026-02-19
kalibb/CVE-2025-68921
★ 0 · 2026-02-06
CVE-2025-66478
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 430 Last push 2026-10-09 (15 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

★ 430 · 2025-12-16
vercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

★ 401 · 2025-12-12
hackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.

★ 157 · 2025-12-10
abtonc/next-cve-2025-66478
★ 11 · 2025-12-08
khadafigans/React2Shell

React2Shell - CVE-2025-66478 RCE Exploit

★ 6 · 2026-02-12
wangxso/CVE-2025-66478-POC

CVE-2025-66478 Proof of Concept

★ 5 · 2025-12-17
abdozkaya/rsc-security-auditor

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…

★ 5 · 2025-12-13
strainxx/react2shell-honeypot

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

★ 4 · 2025-12-08
CVE-2025-49844
FRESH PoCHOTMULTI PoC
PoCs 19 ★ 345 Last push 2026-10-09 (16 hours, 1 minute ago)

Fetching description from NVD…

Show 8 of 19 repositories
raminfp/redis_exploit

CVE-2025-49844 (RediShell)

★ 345 · 2025-10-07
dwisiswant0/CVE-2025-49844

CVE-2025-49844 – Redis Lua Parser Use-After-Free

★ 66 · 2025-10-07
saneki/cve-2025-49844

Proof-of-concept for CVE-2025-49844

★ 25 · 2025-11-20
lastvocher/redis-CVE-2025-49844
★ 14 · 2025-10-07
pedrorichil/CVE-2025-49844
★ 6 · 2025-10-08
Zain3311/CVE-2025-49844

🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.

★ 2 · 2026-10-09
MiclelsonCN/CVE-2025-49844_POC

CVE-2025-49844 POC

★ 2 · 2025-10-09
ksnnd32/redis_exploit

🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.

★ 1 · 2026-10-09
CVE-2025-32463
FRESH PoCHOTMULTI PoC
PoCs 69 ★ 529 Last push 2026-10-09 (16 hours, 6 minutes ago)

Fetching description from NVD…

Show 8 of 69 repositories
pr0v3rbs/CVE-2025-32463_chwoot

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

★ 529 · 2025-11-19
kh4sh3i/CVE-2025-32463

Local Privilege Escalation to Root via Sudo chroot in Linux

★ 476 · 2025-07-02
MohamedKarrab/CVE-2025-32463

Privilege escalation to root using sudo chroot, NO NEED for gcc installed.

★ 48 · 2025-10-06
K1tt3h/CVE-2025-32463-POC

CVE-2025-32463 Proof of concept

★ 30 · 2025-07-01
1xPwn/CVE-2025-32463

This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.

★ 26 · 2026-08-12
mirchr/CVE-2025-32463-sudo-chwoot

PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability

★ 25 · 2025-07-05
zinzloun/CVE-2025-32463

# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so

★ 14 · 2025-07-14
AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.

★ 11 · 2025-07-21
CVE-2026-24046
NEWHIGHFRESH PoC
CVSS 7.1 HIGH CWE-22, CWE-59 Published 2026-01-21 PoCs 1 ★ 0 Last push 2026-10-09 (16 hours, 13 minutes ago) Discovered 2026-10-09 14:08

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Show 1 repositories
Rem1L/cve-2026-24046-poc
★ 0 · 2026-10-09
CVE-2012-2459
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-09 (17 hours, 7 minutes ago)

Fetching description from NVD…

Show 2 repositories
systemslibrarian/crypto-lab-merkle-proofs

Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage and CVE-2012…

★ 0 · 2026-10-09
condeDeveloper/arvore-merkle

Arvore de Merkle do zero em C# e .NET 8: provas de pertencimento, esquemas Bitcoin e RFC 6962, e a CVE-2012-2459 demonstrada

★ 0 · 2026-09-25
CVE-2024-36774
NEWHIGHFRESH PoC
CVSS 7.2 HIGH CWE-434 Published 2024-06-06 PoCs 1 ★ 0 Last push 2026-10-09 (17 hours, 14 minutes ago) Discovered 2026-10-09 14:08

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Show 1 repositories
CVE-2026-24088
FRESH PoC
PoCs 1 ★ 3 Last push 2026-10-09 (17 hours, 20 minutes ago)

Fetching description from NVD…

Show 1 repositories
aniketlab/POCO-M7-Plus-Jailbreak

Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)

★ 3 · 2026-10-09
CVE-2026-28775
NEWCRITICALFRESH PoC
CVSS 10.0 CRITICAL CWE-1188 Published 2026-03-04 PoCs 1 ★ 0 Last push 2026-10-09 (17 hours, 50 minutes ago) Discovered 2026-10-09 14:08

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Show 1 repositories
Udyz/CVE-2026-28775

CVE-2026-28775 SNMP RCE

★ 0 · 2026-10-09
CVE-2026-43499
FRESH PoCHOTMULTI PoC
PoCs 158 ★ 1702 Last push 2026-10-09 (18 hours, 6 minutes ago)

Fetching description from NVD…

Show 8 of 158 repositories
YuKongA/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

★ 1702 · 2026-10-08
BuSung-dev/Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

★ 1381 · 2026-09-03
alex193a/Root-My-Pixel

Jailbreak supported Google Pixel phones with CVE-2026-43499

★ 429 · 2026-09-13
JoinChang/ghostlock-oneplus

GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader

★ 400 · 2026-09-17
x-spy/CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

★ 251 · 2026-07-15
hmascs/KSuRoot

KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…

★ 235 · 2026-10-02
MobiusM/CVE-2026-43499

CVE-2026-43499 PoC

★ 160 · 2026-06-27
Linuxoid-cn/CVE-2026-43499-Poc-Analysis

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

★ 108 · 2026-07-30
CVE-2026-22732
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-09 (19 hours, 14 minutes ago)

Fetching description from NVD…

Show 3 repositories
semgrep/cve-2026-22732-demo

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

★ 0 · 2026-04-07
moderneinc/rewrite-cve-2026-22732
★ 0 · 2026-10-09
CVE-2021-44228
FRESH PoCHOTMULTI PoC
PoCs 456 ★ 3426 Last push 2026-10-09 (19 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 456 repositories
fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

★ 3426 · 2022-11-23
kozmer/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

★ 1846 · 2024-02-12
christophetd/log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

★ 1141 · 2024-04-26
Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

★ 950 · 2022-01-15
logpresso/CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

★ 862 · 2022-04-07
f0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

★ 841 · 2023-06-13
mergebase/log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…

★ 640 · 2022-03-10
corretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

★ 497 · 2022-10-24
CVE-2026-64561
FRESH PoCMULTI PoC
PoCs 8 ★ 3 Last push 2026-10-09 (19 hours, 51 minutes ago)

Fetching description from NVD…

Show 8 repositories
HORKimhab/CVE-2026-64561

CVE-2026-64561

★ 3 · 2026-08-07
aarif450/Zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

★ 2 · 2026-10-09
HackSpeak/CVE-2026-64561

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing

★ 2 · 2026-08-08
Aoripus-LTD/Zapscape-Fix

Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)

★ 1 · 2026-08-07
suominen/zapscape

Tracking Zapscape (CVE-2026-64561), the KVM/x86 shadow-MMU guest-to-host escape

★ 0 · 2026-09-27
aarif450/aarif450.github.io

Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.

★ 0 · 2026-08-09
chuzhongyun/CVE-2026-64561-Kernel-Fix

Linux 内核升级指南 - 修复 CVE-2026-64561

★ 0 · 2026-08-08
hitechcloud-vietnam/Zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

★ 0 · 2026-10-03
CVE-2026-88771
CRITICALFRESH PoCMULTI PoC
CVSS 9.5 CRITICAL CWE-20 Published 2026-09-27 PoCs 12 ★ 23 Last push 2026-10-09 (19 hours, 53 minutes ago)

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Show 8 of 12 repositories
ThomasPoppelgaard/netscaler-ctx697096-checker

Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…

★ 18 · 2026-10-08
technion/netscaler_scanner

Tooling related to CVE-2026-88771 and CVE-2026-88772

★ 1 · 2026-10-09
grupooruss/netscaler-defensive-checker

Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778

★ 1 · 2026-10-08
EXEcution-py/CVE-2026-88771-POC

Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total

★ 0 · 2026-09-28
techupdate24/citrix-netscaler-cve-2026-88771-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-28
SwiftSecur/CVE-2026-88771-HuntScript

A detection/hunting script for compromise related to CVE-2026-88771

★ 0 · 2026-09-29
CVE-2025-24257
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 4 minutes ago)

Fetching description from NVD…

Show 1 repositories
Learningdisordercapital35/CVE_2025_24257----NOT-MINE

Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis

★ 0 · 2026-10-09
CVE-2026-24291
FRESH PoCMULTI PoC
PoCs 5 ★ 4 Last push 2026-10-09 (20 hours, 6 minutes ago)

Fetching description from NVD…

Show 5 repositories
lennertdefauw/CVE-2026-24291

Windows privilege escalation using RegPwn

★ 4 · 2026-03-19
tracyliving606/RegPwn

Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions

★ 4 · 2026-10-09
n0isegat3/RegPwnBRc4BOF

Brute Ratel C4 BOF of the CVE-2026-24291

★ 3 · 2026-03-18
ZeroDayVPN/CVE-2026-24291

About 2026 Guide: Bypass User Account Control Prompts on Windows 11

★ 1 · 2026-07-12
uname1able/CVE-2026-24291
★ 0 · 2026-03-26
CVE-2026-2472
FRESH PoC
PoCs 2 ★ 5 Last push 2026-10-09 (20 hours, 9 minutes ago)

Fetching description from NVD…

Show 2 repositories
JoshuaProvoste/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

Technical PoC for CVE-2026-2472 (GCP-2026-011): Unauthenticated and Stored Cross-Site Scripting (XSS) in google-cloud-aiplatform _genai/_evals_visualization (V…

★ 5 · 2026-02-27
megafart1/CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

★ 2 · 2026-10-09
CVE-2026-107406
NEWCRITICALFRESH PoC
CVSS 9.5 CRITICAL CWE-119 Published 2026-10-08 PoCs 2 ★ 0 Last push 2026-10-09 (20 hours, 10 minutes ago) Discovered 2026-10-09 14:08

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Show 2 repositories
techupdate24/citrix-netscaler-rce-cve-2026-107406

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-09
ApexBreach/CVE-2026-107406-Poc
★ 0 · 2026-10-09
CVE-2026-20841
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 141 Last push 2026-10-09 (20 hours, 11 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
BTtea/CVE-2026-20841-PoC

PoC

★ 141 · 2026-02-11
patchpoint/CVE-2026-20841
★ 12 · 2026-02-12
atiilla/CVE-2026-20841
★ 5 · 2026-02-12
tangent65536/CVE-2026-20841

PoC for the "Windows Notepad RCE"

★ 2 · 2026-02-11
dogukankurnaz/CVE-2026-20841-PoC

CVE-2026-20841

★ 2 · 2026-02-12
hamzamalik3461/CVE-2026-20841

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

★ 1 · 2026-10-09
SecureWithUmer/CVE-2026-20841

PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…

★ 1 · 2026-02-12
CVE-2024-21762
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 150 Last push 2026-10-09 (20 hours, 30 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
h4x0r-dz/CVE-2024-21762

out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability

★ 150 · 2024-03-16
BishopFox/cve-2024-21762-check

Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762

★ 107 · 2024-07-05
r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check

Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)

★ 16 · 2025-06-29
d0rb/CVE-2024-21762

The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.

★ 12 · 2024-03-17
abrewer251/CVE-2024-21762_FortiNet_PoC

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

★ 4 · 2025-05-22
rdoix/cve-2024-21762-checker
★ 1 · 2024-06-20
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
deFr0ggy/CVE-2024-21762-Checker

This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…

★ 0 · 2024-03-25
CVE-2023-27997
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 134 Last push 2026-10-09 (20 hours, 30 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
BishopFox/CVE-2023-27997-check

Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing

★ 134 · 2024-05-08
lexfo/xortigate-cve-2023-27997

xortigate-cve-2023-27997

★ 63 · 2023-10-12
rio128128/CVE-2023-27997-POC

POC FortiOS SSL-VPN buffer overflow vulnerability

★ 27 · 2023-06-16
delsploit/CVE-2023-27997
★ 9 · 2023-10-12
TechinsightsPro/ShodanFortiOS

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

★ 2 · 2023-07-11
imbas007/CVE-2023-27997-Check
★ 1 · 2023-06-23
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
puckiestyle/cve-2023-27997
★ 0 · 2023-06-23
CVE-2022-40684
FRESH PoCHOTMULTI PoC
PoCs 31 ★ 358 Last push 2026-10-09 (20 hours, 30 minutes ago)

Fetching description from NVD…

Show 8 of 31 repositories
horizon3ai/CVE-2022-40684

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 358 · 2022-10-13
carlosevieira/CVE-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

★ 87 · 2022-10-13
arsolutioner/fortigate-belsen-leak

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

★ 87 · 2025-01-16
Filiplain/Fortinet-PoC-Auth-Bypass

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

★ 16 · 2023-04-02
kljunowsky/CVE-2022-40684-POC

Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 16 · 2023-01-21
TaroballzChen/CVE-2022-40684-metasploit-scanner

An authentication bypass using an alternate path or channel in Fortinet product

★ 14 · 2022-10-27
hughink/CVE-2022-40684
★ 11 · 2022-10-28
qingsiweisan/CVE-2022-40684
★ 9 · 2022-10-26
CVE-2018-13379
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 253 Last push 2026-10-09 (20 hours, 30 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
milo2012/CVE-2018-13379

CVE-2018-13379

★ 253 · 2019-08-14
Blazz3/cve2018-13379-nmap-script

CVE-2018-13379 Script for Nmap NSE.

★ 12 · 2020-09-09
Zeop-CyberSec/fortios_vpnssl_traversal_leak

This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download Forti…

★ 9 · 2021-02-26
B1anda0/CVE-2018-13379

Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本

★ 9 · 2020-12-14
0xHunter/FortiOS-Credentials-Disclosure

CVE-2018-13379 Exploit

★ 6 · 2019-09-24
k4nfr3/CVE-2018-13379-Fortinet

FortiVuln

★ 6 · 2020-11-19
jpiechowka/at-doom-fortigate

Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.

★ 5 · 2024-01-23
Zierax/CVE-2018-13379

CVE-2018-13379 fortiOS vulnerability POC

★ 2 · 2026-02-15
CVE-2023-32434
FRESH PoCHOT
PoCs 2 ★ 144 Last push 2026-10-09 (20 hours, 36 minutes ago)

Fetching description from NVD…

Show 2 repositories
alfiecg24/Trigon

Deterministic kernel exploit based on CVE-2023-32434.

★ 144 · 2026-05-14
rkrakesh524/oob_entry

oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙

★ 0 · 2026-10-09
Page 1 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.