Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

355 results

CVE-2022-21812
NEWHIGHFRESH PoC
CVSS 7.8 HIGH Published 2022-08-18 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 12 minutes ago) Discovered 2026-10-09 14:08

Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Show 1 repositories
CVE-2018-17240
FRESH PoC
PoCs 3 ★ 7 Last push 2026-10-09 (20 hours, 26 minutes ago)

Fetching description from NVD…

Show 3 repositories
Xewdy444/Netgrave

A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)

★ 7 · 2026-10-09
FenrirSec/CVE-2018-17240_exploit

Bash exploit for the CVE-2018-17240 (Netwave Cameras Memory Leak)

★ 1 · 2025-01-07
BBge/CVE-2018-17240

CVE-2018-17240

★ 0 · 2022-06-10
CVE-2026-41089
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 231 Last push 2026-10-09 (20 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
0xABCD01/CVE-2026-41089

Netlogon and CLDAP vulnerability research with a proof of concept.

★ 231 · 2026-06-02
SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

★ 67 · 2026-09-11
HydraSoft/CVE-2026-41089-Netlogon-RCE

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …

★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…

★ 14 · 2026-06-04
hnytgl/CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

★ 13 · 2026-09-26
0xBlackash/CVE-2026-41089

CVE-2026-41089

★ 11 · 2026-06-05
ZeroDayVPN/CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…

★ 5 · 2026-09-29
opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

★ 1 · 2026-10-08
CVE-2026-57827
FRESH PoC
PoCs 4 ★ 16 Last push 2026-10-09 (20 hours, 59 minutes ago)

Fetching description from NVD…

Show 4 repositories
shinthink/CVE-2026-57827

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

★ 16 · 2026-07-29
Mohammad-008/rsfiles-CVE-2026-57827

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

★ 9 · 2026-08-03
jjkk123123/CVE-2026-57827

Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本

★ 1 · 2026-08-06
Candisexterior171/CVE-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

★ 0 · 2026-10-09
CVE-2026-45585
FRESH PoCMULTI PoC
PoCs 11 ★ 7 Last push 2026-10-09 (21 hours ago)

Fetching description from NVD…

Show 8 of 11 repositories
Desireeontrial76/yellowkey-bitlocker

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

★ 7 · 2026-10-09
andrei-majer/bitlocker-hardening

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

★ 5 · 2026-05-24
YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own.…

★ 3 · 2026-09-27
everest90909/YellowKey-WinRE-Remediation

Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…

★ 1 · 2026-05-21
0xBlackash/CVE-2026-45585

CVE-2026-45585

★ 1 · 2026-05-31
bjbakker1984/Yellowkey-mitigation

A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions

★ 0 · 2026-05-20
ChanderManiPandey2022/Yellow-Key-Check

YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)

★ 0 · 2026-06-04
ChanderManiPandey2022/YellowKey-BitLocker-Bypass-CVE-2026-45585-Detect-Fix-Automatically-via-Microsoft-Intune

YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune

★ 0 · 2026-06-08
CVE-2019-7238
FRESH PoCHOTMULTI PoC
PoCs 7 ★ 154 Last push 2026-10-09 (21 hours, 1 minute ago)

Fetching description from NVD…

Show 7 repositories
mpgn/CVE-2019-7238

🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻

★ 154 · 2019-02-25
jas502n/CVE-2019-7238

Nexus Repository Manager 3 Remote Code Execution without authentication < 3.15.0

★ 85 · 2019-08-19
verctor/nexus_rce_CVE-2019-7238

Some debug notes and exploit(not blind)

★ 39 · 2019-07-28
magicming200/CVE-2019-7238_Nexus_RCE_Tool

CVE-2019-7238 Nexus RCE漏洞图形化一键检测工具。CVE-2019-7238 Nexus RCE Vul POC Tool.

★ 24 · 2020-01-15
DannyRavi/nmap-scripts

nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327

★ 2 · 2025-04-20
smallpiggy/CVE-2019-7238

RCE

★ 1 · 2021-05-20
CyberCTF/vulhub-nexus-cve-2019-7238

Vulhub nexus/CVE-2019-7238: Nexus Repository Manager 3 JEXL Injection RCE (CVE-2019-7238), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-3129
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 289 Last push 2026-10-09 (21 hours, 1 minute ago)

Fetching description from NVD…

Show 8 of 33 repositories
ambionics/laravel-exploits

Exploit for CVE-2021-3129

★ 289 · 2021-01-29
zhzyker/CVE-2021-3129

Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)

★ 166 · 2021-12-14
joshuavanderpoll/CVE-2021-3129

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

★ 158 · 2026-05-21
SNCKER/CVE-2021-3129

Laravel debug rce

★ 134 · 2021-01-24
nth347/CVE-2021-3129_exploit

Exploit for CVE-2021-3129

★ 69 · 2021-03-07
crisprss/Laravel_CVE-2021-3129_EXP
★ 18 · 2021-01-27
ajisai-babu/CVE-2021-3129-exp

Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp

★ 13 · 2023-03-04
CVE-2026-10520
FRESH PoCMULTI PoC
PoCs 8 ★ 13 Last push 2026-10-09 (21 hours, 4 minutes ago)

Fetching description from NVD…

Show 8 repositories
0xBlackash/CVE-2026-10520

CVE-2026-10520

★ 4 · 2026-06-11
HORKimhab/CVE-2026-10520-10523

CVE-2026-10520 and CVE-2026-10523

★ 0 · 2026-06-11
error-inside/CVE-2026-10520

Root-Level RCE via OS Command Injection in Ivanti Sentry

★ 0 · 2026-06-18
gduma-phData/patch-CVE-2026-10520

Patch: OGNL injection (Apache Struts)

★ 0 · 2026-08-24
01xJB/CVE-2026-10520-POC

Exploit for CVE-2026-10520 | Ivanti Sentry - OS Command Injection

★ 0 · 2026-10-09
CVE-2026-23744
FRESH PoCMULTI PoC
PoCs 40 ★ 12 Last push 2026-10-09 (21 hours, 4 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …

★ 12 · 2026-06-14
suljov/CVE-2026-23744-Remote-Code-Execution-POC

MCPJam inspector contains a remote code execution

★ 12 · 2026-03-22
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in version…

★ 6 · 2026-07-14
FrenzisRed/CVE-2026-23744

CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC

★ 4 · 2026-03-23
luiskrnr/exploit-CVE-2026-23744

MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…

★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …

★ 3 · 2026-08-11
InzegoSec/CVE-2026-23744

Exploit to MCPJam Inspector <=1.4.2

★ 1 · 2026-03-25
ctzisme/CVE-2026-23744

PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).

★ 1 · 2026-03-26
CVE-2026-31431
FRESH PoCHOTMULTI PoC
PoCs 325 ★ 4074 Last push 2026-10-09 (21 hours, 6 minutes ago)

Fetching description from NVD…

Show 8 of 325 repositories
theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

★ 4074 · 2026-04-29
tgies/copy-fail-c

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

★ 445 · 2026-07-17
badsectorlabs/copyfail-go

A Go implementation of copyfail (CVE-2026-31431)

★ 360 · 2026-05-01
Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…

★ 191 · 2026-05-07
Sndav/CVE-2026-31431-Advanced-Exploit

CVE-2026-31431 纯文件利用

★ 111 · 2026-04-30
painoob/Copy-Fail-Exploit-CVE-2026-31431

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …

★ 109 · 2026-04-29
sgkdev/page_inject

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

★ 76 · 2026-05-06
Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)

★ 63 · 2026-05-03
CVE-2026-31802
FRESH PoC
PoCs 3 ★ 1 Last push 2026-10-09 (21 hours, 12 minutes ago)

Fetching description from NVD…

Show 3 repositories
Jvr2022/CVE-2026-31802

PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.

★ 1 · 2026-03-14
Recorded-texteditor120/CVE-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

★ 1 · 2026-10-09
ridhinva/npm-tar-path-traversal-scanner

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

★ 0 · 2026-08-07
CVE-2016-10134
CRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-89 Published 2017-02-17 PoCs 1 ★ 0 Last push 2026-10-09 (21 hours, 22 minutes ago) Discovered 2026-10-09 03:16

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

Show 1 repositories
CyberCTF/vulhub-zabbix-cve-2016-10134

Vulhub zabbix/CVE-2016-10134: Zabbix latest.php and jsrpc.php SQL Injection (CVE-2016-10134), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-15107
FRESH PoCMULTI PoC
PoCs 42 ★ 66 Last push 2026-10-09 (21 hours, 22 minutes ago)

Fetching description from NVD…

Show 8 of 42 repositories
jas502n/CVE-2019-15107

CVE-2019-15107 Webmin RCE (unauthorized)

★ 66 · 2019-09-02
MuirlandOracle/CVE-2019-15107
★ 56 · 2024-06-01
hannob/webminex

poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)

★ 8 · 2019-12-25
n0obit4/Webmin_1.890-POC

CVE-2019-15107 exploit

★ 7 · 2020-11-19
ruthvikvegunta/CVE-2019-15107

Webmin <=1.920 RCE

★ 6 · 2020-08-12
AdministratorGithub/CVE-2019-15107

CVE-2019-15107 webmin python3

★ 5 · 2019-08-23
AleWong/WebminRCE-EXP-CVE-2019-15107-

Remote Code Execution Vulnerability in Webmin

★ 3 · 2019-11-01
squid22/Webmin_CVE-2019-15107

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

★ 3 · 2020-10-15
CVE-2020-14882
FRESH PoCHOTMULTI PoC
PoCs 37 ★ 4291 Last push 2026-10-09 (21 hours, 22 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…

★ 4291 · 2021-04-04
jas502n/CVE-2020-14882

CVE-2020–14882、CVE-2020–14883

★ 288 · 2020-11-16
GGyao/CVE-2020-14882_ALL

CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。

★ 145 · 2022-03-29
s1kr10s/CVE-2020-14882

CVE-2020–14882 by Jang

★ 29 · 2020-10-29
NS-Sp4ce/CVE-2020-14882

CVE-2020-14882/14883/14750

★ 19 · 2020-11-04
XTeam-Wing/CVE-2020-14882

CVE-2020-14882 Weblogic-Exp

★ 17 · 2020-10-29
adm1in/CodeTest

CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。

★ 13 · 2020-12-29
GGyao/CVE-2020-14882_POC

CVE-2020-14882批量验证工具。

★ 12 · 2020-12-01
CVE-2017-10271
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 515 Last push 2026-10-09 (21 hours, 22 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
shack2/javaserializetools

Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。

★ 515 · 2020-10-01
c0mmand3rOpSec/CVE-2017-10271

WebLogic Exploit

★ 140 · 2018-07-13
kkirsche/CVE-2017-10271

Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)

★ 128 · 2022-09-16
7kbstorm/WebLogic_CNVD_C2019_48814

WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm

★ 115 · 2019-04-25
SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC

★ 105 · 2019-04-29
1337g/CVE-2017-10271

CVE-2017-10271 WEBLOGIC RCE (TESTED)

★ 39 · 2017-12-23
Cymmetria/weblogic_honeypot

WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …

★ 33 · 2020-04-25
Luffin/CVE-2017-10271

CVE-2017-10271 POC

★ 29 · 2018-01-10
CVE-2018-7490
FRESH PoC
PoCs 2 ★ 1 Last push 2026-10-09 (21 hours, 22 minutes ago)

Fetching description from NVD…

Show 2 repositories
qinzhu111/uWSGI-CVE-2018-7490-POC
★ 1 · 2024-06-14
CyberCTF/vulhub-uwsgi-cve-2018-7490

Vulhub uwsgi/CVE-2018-7490: uWSGI PHP Plugin Path Traversal (CVE-2018-7490), run with Isoloom

★ 0 · 2026-10-09
CVE-2020-13942
FRESH PoCMULTI PoC
PoCs 9 ★ 28 Last push 2026-10-09 (21 hours, 22 minutes ago)

Fetching description from NVD…

Show 8 of 9 repositories
eugenebmx/CVE-2020-13942

CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection

★ 28 · 2020-12-21
shifa123/CVE-2020-13942-POC-

CVE-2020-13942 POC + Automation Script

★ 9 · 2020-11-23
lp008/CVE-2020-13942
★ 6 · 2020-11-19
yaunsky/Unomi-CVE-2020-13942

CVE-2020-13942 Apache Unomi 远程代码执行漏洞脚getshell

★ 4 · 2020-12-22
blackmarketer/CVE-2020-13942
★ 3 · 2022-10-12
dev-team-12x/apche_unomi_rce

Apache Unomi CVE-2020-13942: RCE Vulnerabilities

★ 0 · 2021-01-12
Prodrious/CVE-2020-13942
★ 0 · 2021-09-05
CVE-2020-1938
FRESH PoCHOTMULTI PoC
PoCs 40 ★ 422 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
00theway/Ghostcat-CNVD-2020-10487

Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)

★ 422 · 2020-03-09
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner

Cnvd-2020-10487 / cve-2020-1938, scanner tool

★ 294 · 2021-11-26
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read

Tomcat的文件包含及文件读取漏洞利用POC

★ 57 · 2020-02-21
xindongzhuaizhuai/CVE-2020-1938
★ 45 · 2020-03-02
laolisafe/CVE-2020-1938

CVE-2020-1938漏洞复现

★ 38 · 2020-02-21
CVE-2017-12615
FRESH PoCHOTMULTI PoC
PoCs 18 ★ 295 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 18 repositories
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
breaktoprotect/CVE-2017-12615

POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.

★ 112 · 2022-10-09
mefulton/cve-2017-12615

just a python script for cve-2017-12615

★ 11 · 2017-10-01
xiaokp7/Tomcat_PUT_GUI_EXP

Tomcat PUT方法任意文件写入(CVE-2017-12615)exp

★ 11 · 2023-03-14
zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717

CVE-2017-12617 and CVE-2017-12615 for tomcat server

★ 6 · 2017-10-10
1337g/CVE-2017-12615

CVE-2017-12615 Tomcat RCE (TESTED)

★ 4 · 2017-12-26
wsg00d/cve-2017-12615

tomcat-put-cve-2017-12615

★ 3 · 2017-11-01
CVE-2017-11610
FRESH PoC
PoCs 4 ★ 4 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 4 repositories
yaunsky/CVE-2017-11610

Supervisord远程命令执行漏洞脚本

★ 4 · 2020-12-22
ivanitlearning/CVE-2017-11610

Standalone Python ≥3.6 RCE Unauthenticated exploit for Supervisor 3.0a1 to 3.3.2

★ 0 · 2019-11-05
Dungsocool/CVE-2017-11610

Lab 3: Supervisord XML-RPC Remote Code Execution (CVE-2017-11610) - Writeup and Exploit

★ 0 · 2026-05-27
CyberCTF/vulhub-supervisor-cve-2017-11610

Vulhub supervisor/CVE-2017-11610: Supervisord XML-RPC RCE (CVE-2017-11610), run with Isoloom

★ 0 · 2026-10-09
CVE-2023-27524
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 113 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 15 repositories
horizon3ai/CVE-2023-27524

Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset

★ 113 · 2023-09-09
Okaytc/Superset_auth_bypass_check

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

★ 11 · 2023-08-03
tardc/CVE-2023-27524

Apache Superset Auth Bypass (CVE-2023-27524)

★ 10 · 2023-05-09
ZZ-SOCMAP/CVE-2023-27524

Apache Superset Auth Bypass Vulnerability CVE-2023-27524.

★ 3 · 2023-04-27
Ap0dexMe0/CVE-2023-27524

Perform With Apache-SuperSet Leaked Token [CSRF]

★ 3 · 2023-07-24
Cappricio-Securities/CVE-2023-27524

Apache Superset - Authentication Bypass

★ 2 · 2024-06-24
karthi-the-hacker/CVE-2023-27524

Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)

★ 1 · 2024-05-11
CVE-2022-22965
FRESH PoCHOTMULTI PoC
PoCs 99 ★ 376 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 99 repositories
BobTheShoplifter/Spring4Shell-POC

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

★ 376 · 2022-11-09
reznok/Spring4Shell-POC

Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

★ 325 · 2022-08-04
tpt11fb/SpringVulScan

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

★ 155 · 2023-01-23
TheGejr/SpringShell

Spring4Shell - Spring Core RCE - CVE-2022-22965

★ 131 · 2022-04-04
zangcc/CVE-2022-22965-rexbb

CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。

★ 102 · 2023-11-14
alt3kx/CVE-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

★ 100 · 2022-04-07
SecNN/SpringFramework_CVE-2022-22965_RCE

SpringFramework 远程代码执行漏洞CVE-2022-22965

★ 72 · 2022-04-01
4nth0ny1130/spring4shell_behinder

CVE-2022-22965写入冰蝎webshell脚本

★ 62 · 2022-05-10
CVE-2022-22963
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 353 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
hktalent/spring-spel-0day-poc

spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963

★ 353 · 2023-03-05
dinosn/CVE-2022-22963

CVE-2022-22963 PoC

★ 116 · 2022-03-30
darryk10/CVE-2022-22963
★ 34 · 2022-04-15
J0ey17/CVE-2022-22963_Reverse-Shell-Exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vuln…

★ 24 · 2023-03-18
me2nuk/CVE-2022-22963

Spring Cloud Function Vulnerable Application / CVE-2022-22963

★ 19 · 2022-04-01
RanDengShiFu/CVE-2022-22963

CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit

★ 15 · 2022-03-30
kh4sh3i/Spring-CVE

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed …

★ 14 · 2022-03-31
Kirill89/CVE-2022-22963-PoC
★ 9 · 2022-03-30
CVE-2022-22947
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 223 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 62 repositories
lucksec/Spring-Cloud-Gateway-CVE-2022-22947

CVE-2022-22947

★ 223 · 2022-03-03
whwlsfb/cve-2022-22947-godzilla-memshell

CVE-2022-22947 注入Godzilla内存马

★ 208 · 2022-04-26
SecNN/CVE-2022-22947_Rce_Exp

Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947

★ 77 · 2022-11-14
tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway

CVE-2022-22947批量

★ 71 · 2022-03-04
0730Nophone/CVE-2022-22947-

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

★ 59 · 2022-05-16
crowsec-edtech/CVE-2022-22947

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

★ 37 · 2022-03-04
0x7eTeam/CVE-2022-22947

CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell

★ 35 · 2022-03-08
Tas9er/SpringCloudGatewayRCE

SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er

★ 27 · 2022-03-03
CVE-2018-1273
FRESH PoCMULTI PoC
PoCs 7 ★ 58 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 7 repositories
jas502n/cve-2018-1273

Spring Data Commons RCE 远程命令执行漏洞

★ 58 · 2019-04-29
wearearima/poc-cve-2018-1273

POC for CVE-2018-1273

★ 24 · 2018-06-05
knqyf263/CVE-2018-1273

Environment for CVE-2018-1273 (Spring Data Commons)

★ 10 · 2018-08-15
webr0ck/poc-cve-2018-1273
★ 2 · 2018-10-05
cved-sources/cve-2018-1273

cve-2018-1273

★ 0 · 2021-04-15
hdgokani/CVE-2018-1273
★ 0 · 2025-06-25
CyberCTF/vulhub-spring-cve-2018-1273

Vulhub spring/CVE-2018-1273: Spring Data Commons SpEL Injection (CVE-2018-1273), run with Isoloom

★ 0 · 2026-10-09
< Prev Page 2 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.