Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
354PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

354 results

CVE-2026-102422
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 5 hours ago)

Fetching description from NVD…

Show 1 repositories
DevVaibhav07/CVE-2026-102422

CVE-2026-102422 POC

★ 0 · 2026-10-07
CVE-2026-82531
FRESH PoC
PoCs 1 ★ 2 Last push 2026-10-07 (3 days, 5 hours ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-82531

Smarty is vulnerable to code injection through template inheritance. Crafted assigned data can inject a forged SmartyNocache marker into regenerated PHP cache …

★ 2 · 2026-10-07
CVE-2026-74469
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-07 (3 days, 8 hours ago)

Fetching description from NVD…

Show 3 repositories
suominen/diagspill

Tracking DiagSpill (CVE-2026-74469), the Linux kernel SCTP sock_diag heap overflow

★ 0 · 2026-10-07
0xBlackash/CVE-2026-74469

CVE-2026-74469

★ 0 · 2026-09-28
HORKimhab/CVE-2026-74469

CVE-2026-74469 DiagSpill

★ 0 · 2026-09-21
CVE-2026-33439
FRESH PoCMULTI PoC
PoCs 7 ★ 11 Last push 2026-10-07 (3 days, 8 hours ago)

Fetching description from NVD…

Show 7 repositories
TheMalwareGuardian/CVE-2026-33439

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

★ 11 · 2026-05-01
infernosalex/CVE-2026-33439-Python-PoC

Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

★ 4 · 2026-09-12
Ibonok/CVE-2026-33439-PoC

CVE-2026-33439

★ 2 · 2026-04-28
shreyas-malhotra/CVE-2026-33439-OpenAM

Vulnerable endpoint description for CVE-2026-33439 in OpenAM

★ 0 · 2026-04-27
JonasChen0103/CVE-2026-33439-PoC

CVE-2026-33439 OpenAM pre-auth RCE PoC

★ 0 · 2026-09-19
rh33t/CVE-2026-33439-Poc

Proof of concept for CVE-2026-33439, an unauthenticated RCE in OpenAM via Java deserialization

★ 0 · 2026-09-29
amis13/openam-clean

CVE-2026-33439

★ 0 · 2026-10-07
CVE-2026-59358
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 8 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-59358

CVE-2026-59358 - Cloud Foundry UAA - High - Remote - Privilege leftover - user PKCE token as client_credentials Bearer

★ 1 · 2026-10-07
CVE-2022-0185
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 378 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 8 of 11 repositories
Crusaders-of-Rust/CVE-2022-0185

CVE-2022-0185

★ 378 · 2022-04-25
chenaotian/CVE-2022-0185

CVE-2022-0185 POC and Docker and Analysis write up

★ 37 · 2022-05-24
veritas501/CVE-2022-0185-PipeVersion

CVE-2022-0185 exploit rewritten with pipe primitive

★ 16 · 2022-04-05
featherL/CVE-2022-0185-exploit

CVE-2022-0185 exploit

★ 3 · 2022-11-02
dcheng69/CVE-2022-0185-Case-Study
★ 3 · 2024-05-09
khaclep007/CVE-2022-0185
★ 0 · 2022-01-27
sandesh9978/CVE-2022-0185-Analysis-and-Exploit

Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.

★ 0 · 2026-03-20
CVE-2026-19089
FRESH PoC
PoCs 1 ★ 5 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-19089-WooCommerce-Tyche

CVE-2026-19089 WooCommerce Tych Remote Command Execution

★ 5 · 2026-10-07
CVE-2026-11387
FRESH PoC
PoCs 2 ★ 3 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 2 repositories
abraxas/CVE-2026-11387-WooCommerce-SMS-OTP

SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced P…

★ 3 · 2026-10-07
1beelze/CVE-2026-11387
★ 1 · 2026-07-03
CVE-2026-82226
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-82226

CVE-2026-82226 - Tickera - Critical 9.8 - Unauthenticated POST /cart/ - PHP Object Injection

★ 0 · 2026-10-07
CVE-2026-78159
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-78159

CVE-2026-78159 - stellarwp - Critical 9.8 - Unauthenticated POST /wp-comments-post.php - Remote Code Execution

★ 1 · 2026-10-07
CVE-2026-96512
HIGHFRESH PoC
CVSS 7.8 HIGH CWE-863 Published 2026-09-23 PoCs 2 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.

Show 2 repositories
abraxas/CVE-2026-96512

CVE-2026-96512 - sudo - High 7.8 - Authenticated LOCAL TZ=UTC+14 sudo -n /usr/bin/id - Local Privilege Escalation via Time-Window Bypass

★ 0 · 2026-10-07
CVE-2026-22599
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-22599

CVE-2026-22599 - Strapi - Critical 9.3 - Authenticated POST /content-type-builder/content-types - Authenticated SQL Injection (Knex raw defaultTo)

★ 1 · 2026-10-07
CVE-2026-52782
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-52782

CVE-2026-52782 - OpenProject - Critical 9.9 - Authenticated PATCH /projects/{identifier}/settings/project_storages/{id} - Authenticated IDOR (Project Storage F…

★ 0 · 2026-10-07
CVE-2026-61628
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-61628

CVE-2026-61628 - nginx-ignition - High 8.1 - Unauthenticated Privilege Escalation (Administrator Account Creation)

★ 0 · 2026-10-07
CVE-2026-13447
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-13447

CVE-2026-13447 - WordPress - inspireui - Critical 9.8 - Unauthenticated POST /wp-json/api/flutter_user/firebase_sms_v2 - Authentication Bypass

★ 0 · 2026-10-07
CVE-2026-84753
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-84753

CVE-2026-84753 - WPFunnels - Critical 9.8 - Unauthenticated POST /?rest_route=/mint-mail/v1/mint-form-... - PHP Object Injection

★ 1 · 2026-10-07
CVE-2026-75650
FRESH PoCMULTI PoC
PoCs 6 ★ 8 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 6 repositories
fortbridge/stylesmuggler

Private HTTP-only reproduction of CVE-2026-75650 StyleSmuggler

★ 8 · 2026-09-12
dinosn/cve-2026-75650-magento-validation-lab

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

★ 6 · 2026-09-12
disrex-group/stylesmuggler-adobe-patches

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magen…

★ 5 · 2026-09-08
jithinkrishnanrs/stylesmuggler-ioc-toolkit

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence ar…

★ 0 · 2026-09-17
disrex-group/stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-ado…

★ 0 · 2026-09-08
abraxas/CVE-2026-75650

CVE-2026-75650 - Magento Open Source - Critical 10.0 - Unauthenticated POST /graphql - Unauthenticated Remote Code Execution (StyleSmuggler SSTI)

★ 0 · 2026-10-07
CVE-2026-48356
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-48356

CVE-2026-48356 - Magento Open Source - Critical 9.3 - Unauthenticated POST /rest/default/V1/guest-carts/{cartId}/items - Unauthenticated Unrestricted File Uplo…

★ 0 · 2026-10-07
CVE-2026-12793
FRESH PoC
PoCs 3 ★ 5 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 3 repositories
murrez/CVE-2026-12793

CVE-2026-12793 PoC — JetFormBuilder ≤3.6.2 unauth Register User / admin account creation

★ 5 · 2026-09-16
rootxn/CVE-2026-12793
★ 0 · 2026-09-16
abraxas/CVE-2026-12793

CVE-2026-12793 - JetFormBuilder Unauthorized RCE (CRITICAL 9.8)

★ 0 · 2026-10-07
CVE-2026-77991
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-77991

CVE-2026-77991 - joomlaeventmanager.net - Critical - Privileged POST /administrator/index.php - Remote Code Execution

★ 1 · 2026-10-07
CVE-2026-75827
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-75827

CVE-2026-75827 - getgrav - High 8.8 - Unauthenticated GET /poc-form - Arbitrary File Write

★ 0 · 2026-10-07
CVE-2026-15583
FRESH PoC
PoCs 2 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 2 repositories
abraxas/CVE-2026-15583

CVE-2026-15583 - Grafana MCP Server - High 8.6 - Unauthenticated POST /mcp - Unauthenticated Token Exfiltration (X-Grafana-URL Confused Deputy)

★ 1 · 2026-10-07
codeb0ssx/CVE-2026-15583-PoC

Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.

★ 0 · 2026-07-17
CVE-2026-87796
CRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-434 Published 2026-09-17 PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Show 1 repositories
abraxas/CVE-2026-87796

CVE-2026-87796 - Multi Uploader for Gravity Forms <= 1.1.9; Unauthorized RCE (CRITICAL 9.8)

★ 1 · 2026-10-07
CVE-2026-62062
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-62062

CVE-2026-62062 - WordPress - Elementor Website Builder - High 8.8 - Unauthenticated POST /?rest_route=/wp/v2/users&x=elementor... - Cross-Site Request Forgery …

★ 1 · 2026-10-07
CVE-2026-81648
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-81648

CVE-2026-81648 - WordPress - CryptoPayment Gateway - Critical 10.0 - Unauthenticated POST /wp-content/plugins/cryptopayment-gateway/vendor/cryptd/ajax.php - Ar…

★ 0 · 2026-10-07
< Prev Page 10 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.