Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
353 results
PoCs 7
★ 2
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 7 repositories
jayhutajulu1/CVE-2026-43494-PinTheft-PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…
★ 1 · 2026-07-16
suominen/pintheft
Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation
★ 0 · 2026-10-06
tanzz1337/CVE-2026-43494-PinTheft-PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…
★ 0 · 2026-05-25
PoCs 3
★ 0
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 3 repositories
suominen/pppoeject
Tracking PPPoEject (CVE-2026-68121), the Linux kernel PPPoE sendmsg use-after-free
★ 0 · 2026-10-06
PoCs 3
★ 33
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 3 repositories
PoCs 1
★ 0
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 1 repositories
suominen/itscape
Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape
★ 0 · 2026-10-06
PoCs 5
★ 7
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 5 repositories
HackSpeak/CVE-2026-64564
SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing
★ 7 · 2026-08-08
suominen/sctphantom
Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free
★ 1 · 2026-10-06
PoCs 4
★ 2
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 4 repositories
suominen/cifswitch
Tracking CIFSwitch (CVE-2026-46243), the CIFS cifs.spnego key-origin privilege escalation
★ 0 · 2026-10-06
PoCs 4
★ 9
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 4 repositories
HackSpeak/CVE-2026-64531
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research
★ 9 · 2026-08-04
suominen/ovswrap
Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow
★ 0 · 2026-10-06
PoCs 7
★ 6
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 7 repositories
Aoripus-LTD/Januscape-Hotfix
Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — c…
★ 6 · 2026-07-08
ndouglas-cloudsmith/CVE-2026-53359
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerabili…
★ 0 · 2026-07-15
PoCs 12
★ 35
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 8 of 12 repositories
imbas007/CVE-2026-42533
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
★ 35 · 2026-07-27
Daniyal48/ghostlock-vagrant-box
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root p…
★ 1 · 2026-07-20
0xCyberstan/CVE-2026-42533-POC
CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.
★ 1 · 2026-08-05
srkyn/nginx-map-risk-audit
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
★ 0 · 2026-07-20
PoCs 1
★ 1
Last push 2026-10-06 (4 days, 2 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-06 (4 days, 2 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 15
Last push 2026-10-06 (4 days, 3 hours ago)
Fetching description from NVD…
Show 1 repositories
fastify/send
Fork of the send module to deal with CVE-2017-20165
★ 15 · 2026-10-06
PoCs 1
★ 1
Last push 2026-10-06 (4 days, 6 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 5
★ 3
Last push 2026-10-06 (4 days, 6 hours ago)
Fetching description from NVD…
Show 5 repositories
Jenderal92/CVE-2026-8206
Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).
★ 3 · 2026-06-02
PoCs 1
★ 0
Last push 2026-10-06 (4 days, 8 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 85
★ 442
Last push 2026-10-06 (4 days, 8 hours ago)
Fetching description from NVD…
Show 8 of 85 repositories
PolarisLab/S2-045
Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html
★ 23 · 2017-03-07
CVSS 9.1 CRITICAL
CWE-346, CWE-354
Published 2026-09-18
PoCs 1
★ 3
Last push 2026-10-06 (4 days, 9 hours ago)
Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.
Show 1 repositories
CVSS 7.1 HIGH
CWE-79
Published 2026-09-18
PoCs 4
★ 63
Last push 2026-10-06 (4 days, 9 hours ago)
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS.
This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35.
The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
Show 4 repositories
DeathShotXD/Comment2Shell
Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post…
★ 63 · 2026-10-06
686f6c61/POC-WP-CORE-CVE-2026-93485
Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verifica…
★ 1 · 2026-09-26
PoCs 1
★ 0
Last push 2026-10-06 (4 days, 10 hours ago)
Fetching description from NVD…
Show 1 repositories
K1tor/PixelVolte5G
无 Root 开启 Pixel VoLTE/VoNR/5G —— Shizuku 运营商配置覆写助手(适配 Android 17 QPR1 / CVE-2025-48617)
★ 0 · 2026-10-06
CVSS 8.8 HIGH
CWE-1390
Published 2026-10-02
PoCs 1
★ 1
Last push 2026-10-06 (4 days, 11 hours ago)
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-05 (4 days, 13 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-05 (4 days, 16 hours ago)
Fetching description from NVD…
Show 1 repositories
CVSS 7.8 HIGH
CWE-416
Published 2026-09-23
PoCs 1
★ 18
Last push 2026-10-05 (4 days, 16 hours ago)
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Show 1 repositories
rafabd1/VectorFreed
This repository documents the VectorFreed RCE chain and includes a PoC for CVE-2026-96889.
★ 18 · 2026-10-05
PoCs 2
★ 0
Last push 2026-10-05 (4 days, 17 hours ago)
Fetching description from NVD…
Show 2 repositories
PoCs 1
★ 0
Last push 2026-10-05 (4 days, 18 hours ago)
Fetching description from NVD…
Show 1 repositories
jamir0quai/CVE-2026-16444
CVE-2026-16444 — Arbitrary file write on the controller via TeamViewer Classical File Transfer (TV-2026-1008)
★ 0 · 2026-10-05
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.