Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

353 results

CVE-2026-43494
FRESH PoCMULTI PoC
PoCs 7 ★ 2 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-43494

CVE-2026-43494

★ 2 · 2026-05-23
jayhutajulu1/CVE-2026-43494-PinTheft-PoC

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…

★ 1 · 2026-07-16
Koshmare-Blossom/PinTheft-asm

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

★ 1 · 2026-05-28
suominen/pintheft

Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation

★ 0 · 2026-10-06
Kagantua/PinTheft-go

A Go implementation of PinTheft (CVE-2026-43494)

★ 0 · 2026-05-22
tanzz1337/CVE-2026-43494-PinTheft-PoC

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…

★ 0 · 2026-05-25
CVE-2026-68121
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 3 repositories
suominen/pppoeject

Tracking PPPoEject (CVE-2026-68121), the Linux kernel PPPoE sendmsg use-after-free

★ 0 · 2026-10-06
0xBlackash/CVE-2026-68121

CVE-2026-68121

★ 0 · 2026-09-28
HORKimhab/CVE-2026-68121

CVE-2026-68121 PPPoEject

★ 0 · 2026-09-21
CVE-2026-68138
FRESH PoC
PoCs 3 ★ 33 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 3 repositories
aramosf/CVE-2026-68138

CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC

★ 33 · 2026-08-12
suominen/CVE-2026-68138

Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free

★ 0 · 2026-10-06
jangkrikkbozz/CVE-2026-68138

CVE-2026-68138 Linux Local Privilege Escalation Exploit

★ 0 · 2026-08-17
CVE-2026-46316
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
suominen/itscape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

★ 0 · 2026-10-06
CVE-2026-64564
FRESH PoCMULTI PoC
PoCs 5 ★ 7 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 5 repositories
ethanolgolf/CVE-2026-64564

LPE on Deb

★ 7 · 2026-08-10
HackSpeak/CVE-2026-64564

SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing

★ 7 · 2026-08-08
suominen/sctphantom

Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free

★ 1 · 2026-10-06
yandex-cloud-examples/yc-mk8s-sctphantom-mitigation

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)

★ 0 · 2026-08-11
CVE-2026-46243
FRESH PoC
PoCs 4 ★ 2 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 4 repositories
MrForkBomb/CIFSwitch-Checker-CVE-2026-46243

Script para comprobar si la vulnerabilidad de Linux CIFSwitch (CVE-2026-46243) nos afecta. Detecta configuraciones potencialmente vulnerables y mitigaciones si…

★ 2 · 2026-06-02
suominen/cifswitch

Tracking CIFSwitch (CVE-2026-46243), the CIFS cifs.spnego key-origin privilege escalation

★ 0 · 2026-10-06
liamromanis101/cifswitch-check

Detection script for CIFSwitch - CVE-2026-46243

★ 0 · 2026-06-07
0xBlackash/CVE-2026-46243

CVE-2026-46243

★ 0 · 2026-08-03
CVE-2026-64531
FRESH PoC
PoCs 4 ★ 9 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 4 repositories
HackSpeak/CVE-2026-64531

CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research

★ 9 · 2026-08-04
0xBlackash/CVE-2026-64531

CVE-2026-64531

★ 2 · 2026-08-02
suominen/ovswrap

Tracking OVSwrap (CVE-2026-64531), the Open vSwitch datapath netlink overflow

★ 0 · 2026-10-06
CVE-2026-53359
FRESH PoCMULTI PoC
PoCs 7 ★ 6 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 7 repositories
Aoripus-LTD/Januscape-Hotfix

Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — c…

★ 6 · 2026-07-08
0xBlackash/CVE-2026-53359

CVE-2026-53359

★ 4 · 2026-07-08
chuzhongyun/CVE-2026-53359-Kernel-Fix

Linux 内核升级指南 - 修复 CVE-2026-53359

★ 2 · 2026-07-08
xj2268-TA/KVM-Januscape

CVE-2026-53359漏洞补丁

★ 2 · 2026-07-09
HORKimhab/CVE-2026-53359

CVE-2026-53359 - Draft

★ 0 · 2026-07-07
suominen/januscape

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

★ 0 · 2026-10-06
ndouglas-cloudsmith/CVE-2026-53359

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerabili…

★ 0 · 2026-07-15
CVE-2026-42533
FRESH PoCMULTI PoC
PoCs 12 ★ 35 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 8 of 12 repositories
imbas007/CVE-2026-42533

nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.

★ 35 · 2026-07-27
0xCyberstan/CVE-2026-42533-Config-Scanner

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / inf…

★ 30 · 2026-07-20
Daniyal48/ghostlock-vagrant-box

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root p…

★ 1 · 2026-07-20
seguridadentrerios/CVE-2026-42533

Vulnerabilidad en NGINX

★ 1 · 2026-07-22
0xCyberstan/CVE-2026-42533-POC

CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.

★ 1 · 2026-08-05
srkyn/nginx-map-risk-audit

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

★ 0 · 2026-07-20
suominen/CVE-2026-42533

Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow

★ 0 · 2026-10-06
gagaltotal/CVE-2026-42533-nginx

CVE-2026-42533 Nginx

★ 0 · 2026-07-23
CVE-2026-10196
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-06 (4 days, 2 hours ago)

Fetching description from NVD…

Show 1 repositories
0xCyp1337/CVE-2026-10196
★ 1 · 2026-10-06
CVE-2026-105080
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (4 days, 2 hours ago)

Fetching description from NVD…

Show 1 repositories
beyavuz/cve-2026-105080-poc
★ 0 · 2026-10-06
CVE-2017-20165
FRESH PoC
PoCs 1 ★ 15 Last push 2026-10-06 (4 days, 3 hours ago)

Fetching description from NVD…

Show 1 repositories
fastify/send

Fork of the send module to deal with CVE-2017-20165

★ 15 · 2026-10-06
CVE-2026-104905
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-06 (4 days, 6 hours ago)

Fetching description from NVD…

Show 1 repositories
wvllxe/CVE-2026-104905-facturascripts-object-injection

PHP Object Injection -> Arbitrary File Deletion in FacturaScripts <= 2026.66 (CWE-502). PoC + advisory.

★ 1 · 2026-10-06
CVE-2026-8206
FRESH PoCMULTI PoC
PoCs 5 ★ 3 Last push 2026-10-06 (4 days, 6 hours ago)

Fetching description from NVD…

Show 5 repositories
Jenderal92/CVE-2026-8206

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

★ 3 · 2026-06-02
Sanjith1236/CVE-2026-8206-Kirki-Exploit-Analysis

A deep-dive technical reconstruction and impact analysis of CVE-2026-8206—a critical CVSS 9.8 unauthenticated account takeover vulnerability in the WordPress K…

★ 3 · 2026-10-06
Dungsocool/CVE-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

★ 1 · 2026-07-28
izxci/CVE-2026-8206

CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit

★ 0 · 2026-06-17
CVE-2026-53787
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (4 days, 8 hours ago)

Fetching description from NVD…

Show 1 repositories
ChrisSEC2014/amasty-chekout-POC-rce

my poc for CVE-2026-53787

★ 0 · 2026-10-06
CVE-2017-5638
FRESH PoCHOTMULTI PoC
PoCs 85 ★ 442 Last push 2026-10-06 (4 days, 8 hours ago)

Fetching description from NVD…

Show 8 of 85 repositories
mazen160/struts-pwn

An exploit for Apache Struts CVE-2017-5638

★ 442 · 2018-05-21
Flyteas/Struts2-045-Exp

Struts2 S2-045(CVE-2017-5638)Exp with GUI

★ 61 · 2017-03-13
immunio/apache-struts2-CVE-2017-5638

Demo Application and Exploit

★ 34 · 2017-03-13
jas502n/S2-045-EXP-POC-TOOLS

S2-045 漏洞 POC-TOOLS CVE-2017-5638

★ 25 · 2021-08-18
PolarisLab/S2-045

Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html

★ 23 · 2017-03-07
xsscx/cve-2017-5638

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit

★ 22 · 2017-03-12
jas502n/st2-046-poc

st2-046-poc CVE-2017-5638

★ 21 · 2018-08-17
ret2jazzy/Struts-Apache-ExploitPack

These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)

★ 16 · 2017-03-12
CVE-2026-92701
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-346, CWE-354 Published 2026-09-18 PoCs 1 ★ 3 Last push 2026-10-06 (4 days, 9 hours ago)

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.

Show 1 repositories
muhammad-usama-sardar/intra-handshake-fail

Early Attestation Considered Very Harmful (CVE-2026-92701, CVE-2026-92702, CVE-2026-33697, and more to come)

★ 3 · 2026-10-06
CVE-2026-93485
HIGHFRESH PoC
CVSS 7.1 HIGH CWE-79 Published 2026-09-18 PoCs 4 ★ 63 Last push 2026-10-06 (4 days, 9 hours ago)

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Show 4 repositories
DeathShotXD/Comment2Shell

Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post…

★ 63 · 2026-10-06
686f6c61/POC-WP-CORE-CVE-2026-93485

Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verifica…

★ 1 · 2026-09-26
HORKimhab/CVE-2026-93485

CVE-2026-93485 - Draft or TODO

★ 0 · 2026-09-22
0xBlackash/CVE-2026-93485

CVE-2026-93485

★ 0 · 2026-09-22
CVE-2025-48617
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (4 days, 10 hours ago)

Fetching description from NVD…

Show 1 repositories
K1tor/PixelVolte5G

无 Root 开启 Pixel VoLTE/VoNR/5G —— Shizuku 运营商配置覆写助手(适配 Android 17 QPR1 / CVE-2025-48617)

★ 0 · 2026-10-06
CVE-2026-96940
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-1390 Published 2026-10-02 PoCs 1 ★ 1 Last push 2026-10-06 (4 days, 11 hours ago)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Show 1 repositories
HORKimhab/CVE-2026-96940

CVE-2026-96940

★ 1 · 2026-10-06
CVE-2026-21096
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 13 hours ago)

Fetching description from NVD…

Show 1 repositories
Xen0nize/CVE-2026-21096
★ 0 · 2026-10-05
CVE-2025-14659
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-96889
HIGHFRESH PoC
CVSS 7.8 HIGH CWE-416 Published 2026-09-23 PoCs 1 ★ 18 Last push 2026-10-05 (4 days, 16 hours ago)

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

Show 1 repositories
rafabd1/VectorFreed

This repository documents the VectorFreed RCE chain and includes a PoC for CVE-2026-96889.

★ 18 · 2026-10-05
CVE-2024-40453
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-05 (4 days, 17 hours ago)

Fetching description from NVD…

Show 2 repositories
BwithE/CVE-2024-40453

CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc

★ 0 · 2025-07-12
AC8999/CVE-2024-40453

Python POC for CVE-2024-40453.

★ 0 · 2026-10-05
CVE-2026-16444
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 18 hours ago)

Fetching description from NVD…

Show 1 repositories
jamir0quai/CVE-2026-16444

CVE-2026-16444 — Arbitrary file write on the controller via TeamViewer Classical File Transfer (TV-2026-1008)

★ 0 · 2026-10-05
< Prev Page 12 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.