Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Show 1 repositories
CVE-2026-96940
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live357 results
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
CVE-2026-96940
Fetching description from NVD…
Fetching description from NVD…
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
This repository documents the VectorFreed RCE chain and includes a PoC for CVE-2026-96889.
Fetching description from NVD…
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
Python POC for CVE-2024-40453.
Fetching description from NVD…
CVE-2026-16444 — Arbitrary file write on the controller via TeamViewer Classical File Transfer (TV-2026-1008)
Fetching description from NVD…
SuiteCRM <= 7.15.1, <= 8.10.1 - Authenticated SSRF
Fetching description from NVD…
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation
Fetching description from NVD…
🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)
Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)
CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)
Exploits Tested in Mi A2 Lite and Realme 2 pro
BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…
Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).
EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…
Fetching description from NVD…
Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…
Fetching description from NVD…
Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…
Fetching description from NVD…
FastGPT getTools and runTool SSRF Vulnerability Reproduction
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Educational lab and clean-room reproduction demonstrating the OS command injection pattern in CVE-2026-105134. For defensive research only.
Fetching description from NVD…
r30xlqo6从一个辅助 API 看资源边界:CVE-2026-71486(vLLM)w680rjb2afux
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Runtime exploit monitor for Apple document/image pipelines (iOS/macOS) — EXPMON concept: Frida agent + behavioral rules. First target: the CVE-2026-86950 glyph…
A python tool to detect PDF files exploiting CVE-2026-86950
Out-of-bounds Write (CWE-787)
CVE-2026-86950
Fetching description from NVD…
CVE-2026-46333
CHARON — pre-built PoC for CVE-2026-46333 (Linux ptrace mm==NULL fd theft)
Research on `pidfd_getfd(2)`-based file descriptor leakage from privileged SUID processes. Demonstrates race-condition FD capture against OpenSSH `ssh-keysign`…
Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.
Fetching description from NVD…
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, levera…
Fetching description from NVD…
I found an integer overflow that defeats OCaml's fix for CVE-2026-28364: heap memory disclosure and SIGBUS crashes via Marshal deserialization. PoCs, advisory,…
Fetching description from NVD…
CVE-2026-73570
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
Detection-first, evidence-preserving incident-response toolkit for Zimbra CVE-2026-73570. Includes read-only host checks, IOC feeds, triage, persistence, conta…
CVE-2026-73570
CVE-2026-73570 PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
Fetching description from NVD…
Quick tool for utilizing CVE-2024-31317 on Android
CVE-2024-31317
A command-line utility to exploit Android Zygote injection (CVE-2024-31317)
Detailed discussion of Zygote vulnerability CVE-2024-31317
CVE-2024-31317 Debuggable App Exploit
CVE-2024-31317 Android Zygote命令注入漏洞研究与部署工具 | Android 9-13 漏洞利用框架
Remove Android profile owners/family link with CVE-2024-31317
Fetching description from NVD…
Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacke…
Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)
Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath, OpenSearch, G…
Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs
IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)
Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks (Claude Code, VS…
Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx
🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack
Fetching description from NVD…
ModemManager denial-of-service vulnerability caused by an assertion failure when processing a specially crafted Cell Broadcast Message (CBM).
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.