Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
357PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

357 results

CVE-2025-69256
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-05 (5 days, 7 hours ago)

Fetching description from NVD…

Show 3 repositories
SimoesCTT/CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in Serverless Fram…

★ 0 · 2026-01-28
studiomeyer-io/mcp-server-attestation

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends against mar…

★ 0 · 2026-10-05
studiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server s…

★ 0 · 2026-10-04
CVE-2026-100671
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 11 hours ago)

Fetching description from NVD…

Show 1 repositories
canhieu/cve-2026-100671-poc
★ 0 · 2026-10-05
CVE-2026-86881
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-295 Published 2026-09-14 PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 12 hours ago)

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.

Show 1 repositories
0xcrypto/CVE-2026-86881

Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usa…

★ 0 · 2026-10-05
CVE-2026-40281
FRESH PoC
PoCs 3 ★ 3 Last push 2026-10-05 (5 days, 12 hours ago)

Fetching description from NVD…

Show 3 repositories
MRdark-ops/CVE-2026-40281-exploit

Gotenberg 8.30.1 unauthenticated RCE exploit

★ 3 · 2026-10-04
0xgh057r3c0n/CVE-2026-40281

Gotenberg <= 8.30.1 unauthenticated RCE

★ 0 · 2026-10-01
rabakuku/CVE-2026-40281

A Working PoC For CVE-2026-40281

★ 0 · 2026-10-05
CVE-2024-46987
FRESH PoCMULTI PoC
PoCs 10 ★ 27 Last push 2026-10-04 (5 days, 19 hours ago)

Fetching description from NVD…

Show 8 of 10 repositories
Goultarde/CVE-2024-46987

This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive s…

★ 27 · 2026-05-10
advaitpathak21/CVE-2024-46987

Exploit created using Python

★ 1 · 2026-02-06
L1337Xi/CVE-2024-46987

Path Traversal vulnerability

★ 0 · 2026-02-03
Ik0nw/CVE-2024-46987
★ 0 · 2026-02-04
sparrowhawk1113/Exploit-for-CVE-2024-46987

Exploit for CVE-2024-46987

★ 0 · 2026-02-05
Rival420/CVE-2024-46987

CVE-2024-46987 - Camaleon CMS LFI Exploit

★ 0 · 2026-02-05
ramzerk/CVE-2024-46987

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

★ 0 · 2026-02-09
BLUEBERRYP1LL/CVE-2024-46987

PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)

★ 0 · 2026-02-22
CVE-2018-6242
FRESH PoCHOTMULTI PoC
PoCs 7 ★ 559 Last push 2026-10-04 (5 days, 19 hours ago)

Fetching description from NVD…

Show 7 repositories
DavidBuchanan314/NXLoader

My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)

★ 559 · 2022-12-11
reswitched/rcm-modchips

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

★ 21 · 2018-05-22
austinhartzheim/fusee-gelee

Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) for Tegra processors.

★ 5 · 2022-12-21
nikameru/nxboot

Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")

★ 2 · 2026-10-04
Resi-le/NXLoader

An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability

★ 1 · 2025-12-21
Swiftloke/fusee-toy

Implementation of CVE-2018-6242 (AKA Fusée Gelée, AKA shofel2)

★ 0 · 2022-05-25
oliviaholly/fusee-gelee

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

★ 0 · 2026-03-30
CVE-2023-33107
FRESH PoC
PoCs 2 ★ 7 Last push 2026-10-04 (5 days, 20 hours ago)

Fetching description from NVD…

Show 2 repositories
keto0422/CVE-2023-33107

full exploit code

★ 7 · 2026-03-17
264312431/picohaxx

A kernel exploit for Pico 4 devices based on cve-2023-33107.

★ 7 · 2026-10-04
CVE-2026-72898
FRESH PoCMULTI PoC
PoCs 10 ★ 22 Last push 2026-10-04 (5 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 10 repositories
EQSTLab/CVE-2026-72898

Metabase SQLi

★ 22 · 2026-08-27
0xBlackash/CVE-2026-72898

CVE-2026-72898

★ 8 · 2026-08-13
4minx/CVE-2026-72898

CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection

★ 8 · 2026-08-15
VuxNx/CVE-2026-72898

PoC for CVE-2026-72898

★ 2 · 2026-08-15
ubitquity/Metabase-Setup-Endpoint-SQLi-Fix

CVE-2026-72898-Metabase-SQLi-Fix

★ 1 · 2026-08-15
codeb0ssx/CVE-2026-72898-PoC

CVE-2026-72898 - Metabase

★ 0 · 2026-08-13
Franc-Zar/CVE-2026-72898-safe-detection

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

★ 0 · 2026-08-20
d-maggipinto/CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

★ 0 · 2026-08-26
CVE-2026-83627
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-04 (5 days, 21 hours ago)

Fetching description from NVD…

Show 1 repositories
K52-ai/CVE-2026-83627

CVE-2026-83627 — Hummingbird Performance <= 3.21.0 Unauthenticated RCE. Pure Python exploit. by K52-ai.

★ 0 · 2026-10-04
CVE-2026-13247
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-04 (5 days, 21 hours ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/-Recon-MySQL-SSH-ICA-CVE-2026-13247-Tomcat

Hands-on cybersecurity and CTF labs covering service fingerprinting, MySQL enumeration, HTTP clues, SSH discovery, port probing, host discovery, ICA access pat…

★ 0 · 2026-10-04
CVE-2026-54515
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-04 (5 days, 22 hours ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/jackson-check

jackson-databind + jackson-core 26 条安全公告自查:按坐标逐条求交集给出真正到位的版本(2.18.11/2.21.7/2.22.3/3.1.7/3.2.3,2.21.6 已不够);扫源码降噪告诉你真中几条;含 1 条 GitHub 全局库未收录、Dependabot 不报的(jack…

★ 0 · 2026-10-04
CVE-2026-103355
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-04 (6 days ago)

Fetching description from NVD…

Show 1 repositories
Hassham1/CVE-2026-103355-unlimited-elements-sqli-poc

CVE-2026-103355 - Unlimited Elements For Elementor <= 2.0.20 unauthenticated blind SQL injection via terms-listing identifiers (CVSS 9.3): Docker validation la…

★ 1 · 2026-10-04
CVE-2026-104356
FRESH PoC
PoCs 1 ★ 2 Last push 2026-10-04 (6 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
wvllxe/CVE-2026-104356-pictshare-weak-delete-code

Predictable delete_code via rand() in PictShare < 3.7.1 (CWE-338). PoC + advisory writeup.

★ 2 · 2026-10-04
CVE-2026-104051
FRESH PoC
PoCs 1 ★ 2 Last push 2026-10-04 (6 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
wvllxe/CVE-2026-104051-pictshare-info-disclosure

Sensitive info disclosure via info API in PictShare < 3.7.1 (CWE-522). PoC + advisory writeup.

★ 2 · 2026-10-04
CVE-2026-100520
FRESH PoC
PoCs 1 ★ 4 Last push 2026-10-04 (6 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
wvllxe/CVE-2026-100520-laranode-path-traversal

Path Traversal -> RCE in Laranode < 1.2.1 (CWE-22). PoC + advisory writeup.

★ 4 · 2026-10-04
CVE-2026-104991
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-04 (6 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
wvllxe/CVE-2026-104991

CVE-2026-104991 — Missing Authorization (BOLA/IDOR) in Phproject REST API read/comment endpoints

★ 0 · 2026-10-04
CVE-2026-92084
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-94 Published 2026-10-03 PoCs 1 ★ 0 Last push 2026-10-04 (6 days, 4 hours ago)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.

Show 1 repositories
Hassham1/CVE-2026-92084-beaver-builder-shortcode-poc

CVE-2026-92084 — Beaver Builder Lite <= 2.11.0.5 unauthenticated arbitrary shortcode execution via Sidebar module widget output (CVSS 9.1): Docker validation l…

★ 0 · 2026-10-04
CVE-2026-19632
FRESH PoC
PoCs 3 ★ 2 Last push 2026-10-04 (6 days, 4 hours ago)

Fetching description from NVD…

Show 3 repositories
YonLiud/CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

★ 2 · 2026-08-26
DeadExpl0it/CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

★ 0 · 2026-08-27
TheJesterrrr/CVE-2026-19632
★ 0 · 2026-10-04
CVE-2025-49144
FRESH PoCMULTI PoC
PoCs 8 ★ 89 Last push 2026-10-04 (6 days, 5 hours ago)

Fetching description from NVD…

Show 8 repositories
TheTorjanCaptain/CVE-2025-49144_PoC

CVE-2025-49144 PoC for security researchers to test and try.

★ 89 · 2025-06-30
Vr00mm/CVE-2025-49144

PoC CVE-2025-49144

★ 6 · 2025-06-27
b0ySie7e/Notepad-8.8.1_CVE-2025-49144

Proof of Concept (PoC) that exploits the CVE-2025-49144 vulnerability in the Notepad++ 8.8.1 installer.

★ 6 · 2025-06-29
assad12341/notepad-v8.8.1-LPE-CVE-

CVE-2025-49144 * Notepad++ v8.8.1 * SYSTEM-level POC

★ 0 · 2025-06-26
timsonner/CVE-2025-49144-Research
★ 0 · 2025-07-02
GiZcesi/HJregsvr32

Educational PoC for CVE-2025-49144 (regsvr32 LOLBIN) — authorized lab use only

★ 0 · 2026-10-04
onniio/CVE-2025-49144
★ 0 · 2025-09-17
havertz2110/CVE-2025-49144-PoC

This is my reproduce PoC for CVE-2025-49144

★ 0 · 2026-03-20
CVE-2026-25253
FRESH PoCMULTI PoC
PoCs 10 ★ 93 Last push 2026-10-04 (6 days, 9 hours ago)

Fetching description from NVD…

Show 8 of 10 repositories
ethiack/moltbot-1click-rce

Clawdbot/Moltbot/OpenClaw One-click RCE PoC 🦞 (CVE-2026-25253)

★ 93 · 2026-01-27
adibirzu/openclaw-security-monitor

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

★ 48 · 2026-10-04
al4n4n/CVE-2026-25253-research
★ 7 · 2026-02-08
FrigateCaptain/openclaw_vulnerabilities_and_solutions

> OpenClaw security audit and hardened deployment guide — known vulnerabilities (CVE-2026-25253, malicious skills, credential leakage), architectural mitigatio…

★ 2 · 2026-09-03
EQSTLab/CVE-2026-25253

OpenClaw Authentication Token Exfiltration

★ 2 · 2026-05-20
KajzingerAkos/CVE-2026-25253

CVE-2026-25253: One-Click RCE in OpenClaw via Auth Token Theft

★ 1 · 2026-04-18
siyad01/agentbox

Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.

★ 1 · 2026-05-11
yym8538/CVE-2026-25253
★ 1 · 2026-08-21
CVE-2026-15911
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-04 (6 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
rahulreddykarne/CVE-2026-15911-Confluent_Kafka

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

★ 0 · 2026-10-04
CVE-2025-60787
FRESH PoCMULTI PoC
PoCs 9 ★ 10 Last push 2026-10-03 (6 days, 16 hours ago)

Fetching description from NVD…

Show 8 of 9 repositories
gunzf0x/CVE-2025-60787

PoC for CVE-2025-60787 - Authenticated RCE in motionEye for all versions up to 0.43.1b4 (included)

★ 10 · 2026-03-08
lil0xplorer/CVE-2025-60787_PoC
★ 2 · 2026-03-08
Rohitberiwala/CVE-2025-60787-MotionEye-RCE

Professional PoC for CVE-2025-60787: Remote Code Execution in MotionEye (<= 0.43.1b4). This exploit demonstrates an OS Command Injection vulnerability through …

★ 1 · 2026-03-12
prabhatverma47/CVE-2025-60787

CVE-2025-60787 Poc - RCE - MotionEye <= 0.43.1b4

★ 0 · 2025-10-03
d3vn0mi/CVE-2025-60787-POC

Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config

★ 0 · 2026-03-13
agent-skywalker/CVE-2025-60787

MotionEye v0.43.1b4 OS Command Injection

★ 0 · 2026-03-14
ozcanpng/CVE-2025-60787

CVE-2025-60787 motionEye authenticated command injection RCE PoC

★ 0 · 2026-07-10
CVE-2026-27944
FRESH PoCMULTI PoC
PoCs 7 ★ 9 Last push 2026-10-03 (6 days, 16 hours ago)

Fetching description from NVD…

Show 7 repositories
Skynoxk/CVE-2026-27944

Automated exploit script for CVE-2026-27944 (Nginx UI). Downloads/decrypts backups, extracts system secrets, and creates rogue admin accounts for full dashboar…

★ 9 · 2026-03-14
NULL200OK/CVE-2026-27944

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

★ 4 · 2026-03-10
NULL200OK/-nginxui_discover

Nginx UI Discovery Scanner - CVE-2026-27944 Version Detector

★ 2 · 2026-03-11
jake-young-dev/CVE-2026-27944

An educational deep-dive into CVE-2026-27944

★ 1 · 2026-05-06
karimelsheikh1/HTB-Snapped-Writeup

HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race condition LPE) to …

★ 1 · 2026-05-07
BimaBalance/Cve-2026-27944-Tools-Exploit

Suka suka lah

★ 1 · 2026-07-05
diamorphine666/CVE-2026-27944

Nginx UI - Backups Decryption (CVE-2026-27944)

★ 0 · 2026-10-03
CVE-2024-51482
FRESH PoCMULTI PoC
PoCs 9 ★ 14 Last push 2026-10-03 (6 days, 16 hours ago)

Fetching description from NVD…

Show 8 of 9 repositories
plur1bu5/CVE-2024-51482-PoC

Authenticated time-based blind SQL injection PoC for ZoneMinder CVE-2024-51482 (v1.37.* <= 1.37.64)

★ 14 · 2026-03-09
BridgerAlderson/CVE-2024-51482

ZenoMinder Blind SQL Injection PoC

★ 9 · 2026-03-08
0xDaeras/CVE-2024-51482-POC

Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

★ 7 · 2026-05-09
BwithE/CVE-2024-51482

CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc

★ 1 · 2025-10-05
Ravi-lk/CVE-2024-51482-ZoneMinder-v1.37.-1.37.64-SQL-Injection-POC

ZoneMinder Time-Based SQL Injection (CVE-2024-51482) Exploit POC

★ 0 · 2026-03-08
lnn0v4/sqli-hunter-CVE-2024-51482-PoC

Scripts en Python para la explotación de CVE-2024-51482 (SQLi en ZoneMinder) — HTB CCTV

★ 0 · 2026-03-11
Erhui-Li/CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP

Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and improves reliabi…

★ 0 · 2026-03-19
c0gnit00/CVE-2024-51482

CVE-2025-51482 POC, Dump Credentials From zm.Users

★ 0 · 2026-07-10
CVE-2026-42589
FRESH PoC
PoCs 3 ★ 4 Last push 2026-10-03 (6 days, 16 hours ago)

Fetching description from NVD…

Show 3 repositories
fineman999/POC_CVE-2026-42589

POC_CVE-2026-42589

★ 4 · 2026-05-30
HackfutSecRoot/-GOTENBERG-RCE-CHAIN

Gotenberg RCE Chain — CVE-2026-42589 + CVE-2026-40281

★ 2 · 2026-10-03
codeb0ssx/CVE-2026-42589xCVE-2026-40281-PoC

CVE-2026-42589 & CVE-2026-40281 - GotenBerg

★ 0 · 2026-10-02
< Prev Page 14 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.