Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
20New in 24h
357PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

357 results

CVE-2026-96940
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-1390 Published 2026-10-02 PoCs 1 ★ 1 Last push 2026-10-06 (4 days, 12 hours ago)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Show 1 repositories
HORKimhab/CVE-2026-96940

CVE-2026-96940

★ 1 · 2026-10-06
CVE-2026-21096
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 14 hours ago)

Fetching description from NVD…

Show 1 repositories
Xen0nize/CVE-2026-21096
★ 0 · 2026-10-05
CVE-2025-14659
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 17 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-96889
HIGHFRESH PoC
CVSS 7.8 HIGH CWE-416 Published 2026-09-23 PoCs 1 ★ 18 Last push 2026-10-05 (4 days, 17 hours ago)

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

Show 1 repositories
rafabd1/VectorFreed

This repository documents the VectorFreed RCE chain and includes a PoC for CVE-2026-96889.

★ 18 · 2026-10-05
CVE-2024-40453
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-05 (4 days, 17 hours ago)

Fetching description from NVD…

Show 2 repositories
BwithE/CVE-2024-40453

CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc

★ 0 · 2025-07-12
AC8999/CVE-2024-40453

Python POC for CVE-2024-40453.

★ 0 · 2026-10-05
CVE-2026-16444
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
jamir0quai/CVE-2026-16444

CVE-2026-16444 — Arbitrary file write on the controller via TeamViewer Classical File Transfer (TV-2026-1008)

★ 0 · 2026-10-05
CVE-2026-69137
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
EntroVyx/CVE-2026-69137

SuiteCRM <= 7.15.1, <= 8.10.1 - Authenticated SSRF

★ 0 · 2026-10-05
CVE-2026-33534
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
EntroVyx/CVE-2026-33534

EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation

★ 0 · 2026-10-05
CVE-2023-45866
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 1896 Last push 2026-10-05 (4 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
pentestfunctions/BlueDucky

🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)

★ 1896 · 2026-02-11
Danyw24/blueXploit

Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)

★ 16 · 2026-07-23
Eason-zz/BluetoothDucky

CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)

★ 16 · 2024-01-15
AvishekDhakal/CVE-2023-45866_EXPLOITS

Exploits Tested in Mi A2 Lite and Realme 2 pro

★ 3 · 2024-09-02
Sergeb250/BlueDucky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…

★ 2 · 2025-08-26
xG3nesis/RustyInjector

Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).

★ 1 · 2025-01-25
hegaz0y/-BuL

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…

★ 1 · 2026-05-31
jjjjjjjj987/cve-2023-45866-py
★ 0 · 2024-01-23
CVE-2021-31624
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 20 hours ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-CTF-Labs-Tabnabbing-Web-Recon-Nmap-Netdiscover-CVE-Labs

Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…

★ 0 · 2026-10-05
CVE-2020-23546
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 20 hours ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-CTF-Labs-Tabnabbing-Web-Recon-Nmap-Netdiscover-CVE-Labs

Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…

★ 0 · 2026-10-05
CVE-2026-88629
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
ExploreIO/CVE-2026-88629-fastgpt-mcp-client-ssrf

FastGPT getTools and runTool SSRF Vulnerability Reproduction

★ 1 · 2026-10-05
CVE-2026-41875
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-105319
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 1 repositories
kashishtopi/CVE-2026-105319
★ 0 · 2026-10-05
CVE-2026-105314
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 1 repositories
kashishtopi/CVE-2026-105314
★ 0 · 2026-10-05
CVE-2026-105134
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 1 repositories
RayanAlmulhim/CVE-2026-105134-lab

Educational lab and clean-room reproduction demonstrating the OS command injection pattern in CVE-2026-105134. For defensive research only.

★ 0 · 2026-10-05
CVE-2026-71486
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
tmvictorpeters/jbo4rgl

r30xlqo6从一个辅助 API 看资源边界:CVE-2026-71486(vLLM)w680rjb2afux

★ 0 · 2026-10-05
CVE-2026-86950
HIGHFRESH PoCMULTI PoC
CVSS 8.8 HIGH CWE-787 Published 2026-09-28 PoCs 5 ★ 9 Last push 2026-10-05 (5 days, 1 hour ago)

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Show 5 repositories
msuiche/hotcell

Runtime exploit monitor for Apple document/image pipelines (iOS/macOS) — EXPMON concept: Frida agent + behavioral rules. First target: the CVE-2026-86950 glyph…

★ 9 · 2026-10-02
decalage2/detect_CVE-2026-86950

A python tool to detect PDF files exploiting CVE-2026-86950

★ 4 · 2026-10-02
DeAurity/CVE-2026-86950-POC

Out-of-bounds Write (CWE-787)

★ 2 · 2026-09-29
34zY/CVE-2026-86950
★ 0 · 2026-10-01
0xBlackash/CVE-2026-86950

CVE-2026-86950

★ 0 · 2026-10-05
CVE-2026-46333
FRESH PoCMULTI PoC
PoCs 5 ★ 41 Last push 2026-10-05 (5 days, 1 hour ago)

Fetching description from NVD…

Show 5 repositories
0xBlackash/CVE-2026-46333

CVE-2026-46333

★ 41 · 2026-05-17
KaraZajac/CHARON

CHARON — pre-built PoC for CVE-2026-46333 (Linux ptrace mm==NULL fd theft)

★ 8 · 2026-05-17
studiogangster/CVE-2026-46333

Research on `pidfd_getfd(2)`-based file descriptor leakage from privileged SUID processes. Demonstrates race-condition FD capture against OpenSSH `ssh-keysign`…

★ 6 · 2026-05-17
st4rburn/public-passwd

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

★ 4 · 2026-05-17
dr4mohamed/CVE-2026-46333
★ 0 · 2026-10-05
CVE-2025-54769
FRESH PoC
PoCs 2 ★ 2 Last push 2026-10-05 (5 days, 1 hour ago)

Fetching description from NVD…

Show 2 repositories
byteReaper77/CVE-2025-54769

A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, levera…

★ 2 · 2025-07-30
tunahantekeoglu/CVE-2025-54769
★ 0 · 2026-10-05
CVE-2026-28364
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 2 hours ago)

Fetching description from NVD…

Show 1 repositories
Akshay-M-Singh/ocaml-marshal-vulnerability

I found an integer overflow that defeats OCaml's fix for CVE-2026-28364: heap memory disclosure and SIGBUS crashes via Marshal deserialization. PoCs, advisory,…

★ 0 · 2026-10-05
CVE-2026-73570
FRESH PoCMULTI PoC
PoCs 9 ★ 4 Last push 2026-10-05 (5 days, 4 hours ago)

Fetching description from NVD…

Show 8 of 9 repositories
HORKimhab/CVE-2026-73570

CVE-2026-73570

★ 4 · 2026-08-25
gabrielunknown/CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

★ 4 · 2026-09-14
jishino567/CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

★ 2 · 2026-08-25
dahnutz/zimbra-cve-2026-73570-ir

Detection-first, evidence-preserving incident-response toolkit for Zimbra CVE-2026-73570. Includes read-only host checks, IOC feeds, triage, persistence, conta…

★ 2 · 2026-10-05
0xBlackash/CVE-2026-73570

CVE-2026-73570

★ 2 · 2026-09-30
BiuTrap/CVE-2026-73570

CVE-2026-73570 PoC

★ 0 · 2026-09-02
INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

★ 0 · 2026-08-28
juanpoch/CVE-2026-73570

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

★ 0 · 2026-09-13
CVE-2024-31317
FRESH PoCMULTI PoC
PoCs 14 ★ 92 Last push 2026-10-05 (5 days, 4 hours ago)

Fetching description from NVD…

Show 8 of 14 repositories
wqry085/PoC-Deployer-System

Quick tool for utilizing CVE-2024-31317 on Android

★ 92 · 2026-02-16
fuhei/CVE-2024-31317

CVE-2024-31317

★ 68 · 2024-12-05
Anonymous941/zygote-injection-toolkit

A command-line utility to exploit Android Zygote injection (CVE-2024-31317)

★ 63 · 2025-12-17
agg23/cve-2024-31317

Detailed discussion of Zygote vulnerability CVE-2024-31317

★ 30 · 2025-08-05
CleoV2/Debuggable-App-Exploit

CVE-2024-31317 Debuggable App Exploit

★ 12 · 2026-03-01
fcy10012/CVE-2024-31317-Deployer

CVE-2024-31317 Android Zygote命令注入漏洞研究与部署工具 | Android 9-13 漏洞利用框架

★ 6 · 2025-12-21
rifting/Zygotroller

Remove Android profile owners/family link with CVE-2024-31317

★ 5 · 2025-08-10
CVE-2026-45321
FRESH PoCMULTI PoC
PoCs 12 ★ 2 Last push 2026-10-05 (5 days, 4 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
Intrudify/mini-shai-hulud-scanner

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacke…

★ 2 · 2026-05-13
fabriziosalmi/tanstack-compromise-checker

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

★ 2 · 2026-10-05
qi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath, OpenSearch, G…

★ 1 · 2026-05-12
shayr1/shai-hulud-scan

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

★ 1 · 2026-05-13
nkopylov/tanscript-exploit-check

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

★ 1 · 2026-05-26
ry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks (Claude Code, VS…

★ 0 · 2026-05-24
Yomisana/are-you-get-tanstack-attack

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

★ 0 · 2026-05-13
Caixa-git/tanstack-shield

🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack

★ 0 · 2026-05-12
CVE-2026-95622
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 5 hours ago)

Fetching description from NVD…

Show 1 repositories
0xSemizzz/CVE-2026-95622

ModemManager denial-of-service vulnerability caused by an assertion failure when processing a specially crafted Cell Broadcast Message (CBM).

★ 0 · 2026-10-05
< Prev Page 13 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.