Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
361PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

361 results

CVE-2022-23221
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 2 repositories
straightSang/H2-database-CVE-2022-23221

vulhub/H2-database/CVE-2022-23221

★ 0 · 2026-09-10
CyberCTF/vulhub-h2database-cve-2022-23221

Vulhub h2database/CVE-2022-23221: H2 Database Console JDBC URL RCE (CVE-2022-23221), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-43798
FRESH PoCHOTMULTI PoC
PoCs 60 ★ 369 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 8 of 60 repositories
jas502n/Grafana-CVE-2021-43798

Grafana Unauthorized arbitrary file reading vulnerability

★ 369 · 2023-02-14
A-D-Team/grafanaExp

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source …

★ 269 · 2025-10-17
pedrohavay/exploit-grafana-CVE-2021-43798

This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).

★ 46 · 2021-12-11
taythebot/CVE-2021-43798

CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)

★ 43 · 2021-12-07
zer0yu/CVE-2021-43798

Grafana Arbitrary File Reading Vulnerability

★ 27 · 2021-12-07
Mr-xn/CVE-2021-43798

CVE-2021-43798:Grafana 任意文件读取漏洞

★ 24 · 2021-12-07
MoCh3n/CVE-2021-43798-grafana_fileread

grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL

★ 17 · 2022-01-27
ScorpionsMAX/CVE-2021-43798-Grafana-POC

CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数

★ 14 · 2021-12-17
CVE-2017-1000028
FRESH PoC
PoCs 2 ★ 1 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 2 repositories
NeonNOXX/CVE-2017-1000028

POC&EXP for GlassFish<4.1.1(not including 4.1.1).

★ 1 · 2023-12-07
CyberCTF/vulhub-glassfish-cve-2017-1000028

Vulhub glassfish/CVE-2017-1000028: GlassFish 4.1 Admin Console Arbitrary File Read (CVE-2017-1000028), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-22205
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 287 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Al1ex/CVE-2021-22205

CVE-2021-22205& GitLab CE/EE RCE

★ 287 · 2022-11-16
inspiringz/CVE-2021-22205

GitLab CE/EE Preauth RCE using ExifTool

★ 238 · 2022-01-16
mr-r3bot/Gitlab-CVE-2021-22205
★ 181 · 2021-11-02
XTeam-Wing/CVE-2021-22205

Pocsuite3 For CVE-2021-22205

★ 86 · 2021-10-28
r0eXpeR/CVE-2021-22205

CVE-2021-22205 Unauthorized RCE

★ 69 · 2021-10-28
whwlsfb/CVE-2021-22205

CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用

★ 23 · 2021-10-30
c0okB/CVE-2021-22205

CVE-2021-22205 RCE

★ 13 · 2022-07-04
keven1z/CVE-2021-22205

CVE-2021-22205 检测脚本,支持getshell和命令执行

★ 12 · 2022-07-25
CVE-2018-16509
FRESH PoCMULTI PoC
PoCs 5 ★ 62 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 5 repositories
farisv/PIL-RCE-Ghostscript-CVE-2018-16509

PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509

★ 62 · 2021-01-06
knqyf263/CVE-2018-16509

CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)

★ 3 · 2019-02-01
rhpco/CVE-2018-16509

CVE-2018-16509 Docker Playground - Ghostscript command execution

★ 1 · 2022-11-07
cved-sources/cve-2018-16509

cve-2018-16509

★ 0 · 2021-04-15
CyberCTF/vulhub-ghostscript-cve-2018-16509

Vulhub ghostscript/CVE-2018-16509: Ghostscript -dSAFER Sandbox Bypass (CVE-2018-16509), run with Isoloom

★ 0 · 2026-10-09
CVE-2020-17519
FRESH PoCMULTI PoC
PoCs 14 ★ 61 Last push 2026-10-09 (10 hours, 53 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
MrCl0wnLab/SimplesApachePathTraversal

Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519

★ 61 · 2024-08-14
B1anda0/CVE-2020-17519

Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)

★ 47 · 2021-01-06
murataydemir/CVE-2020-17519

[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read

★ 8 · 2021-01-10
dolevf/apache-flink-directory-traversal.nse

Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script

★ 3 · 2021-01-06
QmF0c3UK/CVE-2020-17519
★ 1 · 2021-01-06
yaunsky/CVE-2020-17519-Apache-Flink

CVE-2020-17519; Apache Flink 任意文件读取; 批量检测

★ 1 · 2021-01-18
givemefivw/CVE-2020-17519

CVE-2020-17519 Cheetah

★ 1 · 2021-04-17
dev-team-12x/CVE-2020-17519

CVE-2020-17519

★ 0 · 2025-07-19
CVE-2015-1427
FRESH PoCMULTI PoC
PoCs 6 ★ 32 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 6 repositories
t0kx/exploit-CVE-2015-1427

Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container

★ 32 · 2018-04-07
cved-sources/cve-2015-1427

cve-2015-1427

★ 0 · 2021-04-15
xpgdgit/CVE-2015-1427
★ 0 · 2022-08-01
Sebikea/CVE-2015-1427-for-trixie

To test elasticsearch vulnerabillity on newer version of debian

★ 0 · 2024-11-10
CyberCTF/vulhub-elasticsearch-cve-2015-1427

Vulhub elasticsearch/CVE-2015-1427: Elasticsearch 1.4.2 Groovy sandbox escape, run with Isoloom

★ 0 · 2026-10-09
CVE-2014-3120
FRESH PoCMULTI PoC
PoCs 5 ★ 6 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 5 repositories
echohtp/ElasticSearch-CVE-2014-3120

POC Code to exploite CVE-2014-3120

★ 6 · 2014-07-07
jeffgeiger/es_inject

Demonstration of CVE-2014-3120

★ 0 · 2014-05-13
xpgdgit/CVE-2014-3120
★ 0 · 2022-08-01
Dungsocool/CVE-2014-3120
★ 0 · 2026-05-31
CyberCTF/vulhub-elasticsearch-cve-2014-3120

Vulhub elasticsearch/CVE-2014-3120: Elasticsearch MVEL Dynamic Script RCE (CVE-2014-3120), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-17564
FRESH PoCMULTI PoC
PoCs 7 ★ 16 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 7 repositories
Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget

Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at https://w…

★ 16 · 2022-12-10
fairyming/CVE-2019-17564

CVE-2019-17564:Apache Dubbo反序列化漏洞

★ 8 · 2020-02-24
Jaky5155/CVE-2019-17564

CVE-2019-17564 Apache Dubbo deserialization RCE

★ 2 · 2020-02-13
Hu3sky/CVE-2019-17564

CVE-2019-17564 : Apache Dubbo Deserialization Remote Code Execution

★ 1 · 2020-02-14
r00t4dm/CVE-2019-17564
★ 0 · 2020-02-12
Exploit-3389/CVE-2019-17564
★ 0 · 2020-02-17
CyberCTF/vulhub-dubbo-cve-2019-17564

Vulhub dubbo/CVE-2019-17564: Apache Dubbo HTTP Protocol Deserialization (CVE-2019-17564), run with Isoloom

★ 0 · 2026-10-09
CVE-2018-7600
FRESH PoCHOTMULTI PoC
PoCs 55 ★ 600 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 55 repositories
dreadlocked/Drupalgeddon2

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

★ 600 · 2021-01-08
a2u/CVE-2018-7600

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

★ 353 · 2019-03-29
pimps/CVE-2018-7600

Exploit for Drupal 7 <= 7.57 CVE-2018-7600

★ 141 · 2018-04-26
g0rx/CVE-2018-7600-Drupal-RCE

CVE-2018-7600 Drupal RCE

★ 113 · 2018-04-18
firefart/CVE-2018-7600

CVE-2018-7600 - Drupal 7.x RCE

★ 71 · 2018-04-18
lorddemon/drupalgeddon2

Exploit for CVE-2018-7600.. called drupalgeddon2,

★ 11 · 2018-04-19
r3dxpl0it/CVE-2018-7600

CVE-2018-7600 POC (Drupal RCE)

★ 9 · 2020-08-31
zhzyker/CVE-2018-7600-Drupal-POC-EXP

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

★ 8 · 2020-04-07
CVE-2014-3704
FRESH PoCMULTI PoC
PoCs 7 ★ 3 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 7 repositories
Neldeborg/Drupalgeddon-Python3

An rewritten POC on the CVE-2014-3704

★ 3 · 2025-01-06
happynote3966/CVE-2014-3704
★ 1 · 2018-07-17
joaomorenorf/CVE-2014-3704

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for M…

★ 1 · 2025-02-02
AleDiBen/Drupalgeddon

CVE-2014-3704 aka Drupalgeddon - Form-Cache Injection Method

★ 0 · 2022-10-18
fbm31/Audit-BlackBox-Web-to-Root

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade ver…

★ 0 · 2025-12-31
adfortunato/metasploitable3-pentest-writeup

Full home-lab penetration test of Rapid7's Metasploitable3 (Ubuntu 14.04) from Parrot OS. Covers recon, Drupalgeddon (CVE-2014-3704) RCE, SSH credential reuse,…

★ 0 · 2026-09-13
CyberCTF/vulhub-drupal-cve-2014-3704

Vulhub drupal/CVE-2014-3704: Drupal 7.31 Drupalgeddon SQL Injection (CVE-2014-3704), run with Isoloom

★ 0 · 2026-10-09
CVE-2022-34265
FRESH PoCHOTMULTI PoC
PoCs 5 ★ 124 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 5 repositories
aeyesec/CVE-2022-34265

PoC for CVE-2022-34265 (Django)

★ 124 · 2022-07-30
ZhaoQi99/CVE-2022-34265

PoC for CVE-2022-34265

★ 4 · 2022-08-26
traumatising/CVE-2022-34265

CVE-2022-34265 Vulnerability

★ 3 · 2022-07-13
CyberCTF/vulhub-django-cve-2022-34265

Vulhub django/CVE-2022-34265: Django Trunc and Extract SQL Injection (CVE-2022-34265), run with Isoloom

★ 0 · 2026-10-09
CVE-2017-12635
FRESH PoCMULTI PoC
PoCs 5 ★ 10 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 5 repositories
assalielmehdi/CVE-2017-12635

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

★ 10 · 2019-12-15
Dungsocool/CVE-2017-12635_36
★ 0 · 2026-05-29
Darabium/couchdb-exploit

This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Pr…

★ 0 · 2026-09-19
CyberCTF/vulhub-couchdb-cve-2017-12635

Vulhub couchdb/CVE-2017-12635: Apache CouchDB Privilege Escalation (CVE-2017-12635), run with Isoloom

★ 0 · 2026-10-09
CVE-2010-2861
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 2 repositories
greysneakthief/14641-v2

Redux Python3 Version of CVE-2010-2861

★ 0 · 2025-10-22
CyberCTF/vulhub-coldfusion-cve-2010-2861

Vulhub coldfusion/CVE-2010-2861: Adobe ColdFusion 8 Directory Traversal (CVE-2010-2861), run with Isoloom

★ 0 · 2026-10-09
CVE-2022-46169
FRESH PoCMULTI PoC
PoCs 37 ★ 47 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
0xf4n9x/CVE-2022-46169

CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.

★ 47 · 2022-12-08
FredBrave/CVE-2022-46169-CACTI-1.2.22

This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.

★ 42 · 2023-09-11
sAsPeCt488/CVE-2022-46169

PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22

★ 29 · 2023-05-05
ariyaadinatha/cacti-cve-2022-46169-exploit

This is poc of CVE-2022-46169 authentication bypass and remote code execution

★ 15 · 2023-05-18
c3rrberu5/CVE-2022-46169

Exploit to CVE-2022-46169 vulnerability

★ 9 · 2023-01-16
sh4den/CVE-2022-46169

Cacti Unauthenticated Command Injection

★ 3 · 2026-07-06
N1arut/CVE-2022-46169_POC

RCE POC for CVE-2022-46169

★ 3 · 2023-01-17
icebreack/CVE-2022-46169

Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)

★ 3 · 2023-04-13
CVE-2014-6271
FRESH PoCHOTMULTI PoC
PoCs 95 ★ 232 Last push 2026-10-09 (10 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 95 repositories
opsxcq/exploit-CVE-2014-6271

Shellshock exploit + vulnerable environment

★ 232 · 2023-05-11
scottjpack/shellshock_scanner

Python Scanner for "ShellShock" (CVE-2014-6271)

★ 46 · 2014-09-29
hmlio/vaas-cve-2014-6271

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

★ 22 · 2019-10-08
b4keSn4ke/CVE-2014-6271

Shellshock exploit aka CVE-2014-6271

★ 15 · 2022-04-01
cj1324/CGIShell

shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI

★ 13 · 2014-10-02
francisck/shellshock-cgi

A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server

★ 12 · 2015-06-19
indiandragon/Shellshock-Vulnerability-Scan

Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock

★ 11 · 2021-08-31
npm/ansible-bashpocalypse

Patch for CVE-2014-6271

★ 6 · 2014-09-24
CVE-2018-8715
HIGHFRESH PoC
CVSS 8.1 HIGH CWE-287 Published 2018-03-15 PoCs 1 ★ 0 Last push 2026-10-09 (10 hours, 55 minutes ago) Discovered 2026-10-09 03:16

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Show 1 repositories
CyberCTF/vulhub-appweb-cve-2018-8715

Vulhub appweb/CVE-2018-8715: Appweb Digest Authentication Bypass (CVE-2018-8715), run with Isoloom

★ 0 · 2026-10-09
CVE-2020-13945
FRESH PoC
PoCs 2 ★ 8 Last push 2026-10-09 (10 hours, 55 minutes ago)

Fetching description from NVD…

Show 2 repositories
YutuSec/Apisix_Crack

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

★ 8 · 2022-05-09
CyberCTF/vulhub-apisix-cve-2020-13945

Vulhub apisix/CVE-2020-13945: Apache APISIX Default Admin Token RCE (CVE-2020-13945), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-25646
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 1073 Last push 2026-10-09 (10 hours, 55 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
1n7erface/PocList

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…

★ 1073 · 2023-05-11
yaunsky/cve-2021-25646

Apache Druid 远程代码执行;检测脚本

★ 17 · 2021-02-03
j2ekim/CVE-2021-25646

Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646

★ 4 · 2021-12-12
k7pro/CVE-2021-25646-exp

CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具

★ 4 · 2025-02-18
givemefivw/CVE-2021-25646

CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本

★ 3 · 2021-04-15
lp008/CVE-2021-25646
★ 2 · 2021-02-03
Ormicron/CVE-2021-25646-GUI

CSharp CVE-2021-25646-GUI

★ 1 · 2021-02-05
CVE-2024-28752
FRESH PoC
PoCs 2 ★ 1 Last push 2026-10-09 (10 hours, 55 minutes ago)

Fetching description from NVD…

Show 2 repositories
ReaJason/CVE-2024-28752

Apache CXF SSRF CVE-2024-28752

★ 1 · 2025-05-10
CyberCTF/vulhub-apache-cxf-cve-2024-28752

Vulhub apache-cxf/CVE-2024-28752: Apache CXF Aegis DataBinding SSRF (CVE-2024-28752), run with Isoloom

★ 0 · 2026-10-09
CVE-2023-46604
FRESH PoCHOTMULTI PoC
PoCs 40 ★ 126 Last push 2026-10-09 (10 hours, 55 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ

Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)

★ 126 · 2024-01-20
Catherines77/ActiveMQ-EXPtools

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

★ 83 · 2026-06-27
Arlenhiack/ActiveMQ-RCE-Exploit

ActiveMQ RCE (CVE-2023-46604) 回显利用工具

★ 44 · 2024-09-13
evkl1d/CVE-2023-46604
★ 41 · 2023-11-06
trganda/ActiveMQ-RCE

CVE-2023-46604

★ 28 · 2023-10-26
duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell

This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserializa…

★ 19 · 2024-01-24
justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp

CVE-2023-46604 Apache ActiveMQ RCE exp 基于python

★ 5 · 2023-11-08
NKeshawarz/CVE-2023-46604-RCE
★ 4 · 2023-11-18
CVE-2016-3088
FRESH PoCMULTI PoC
PoCs 9 ★ 83 Last push 2026-10-09 (10 hours, 55 minutes ago)

Fetching description from NVD…

Show 8 of 9 repositories
Catherines77/ActiveMQ-EXPtools

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

★ 83 · 2026-06-27
YutuSec/ActiveMQ_Crack

ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。

★ 18 · 2022-04-02
Ma1Dong/ActiveMQ_putshell-CVE-2016-3088

ActiveMQ_putshell直接获取webshell

★ 15 · 2020-08-01
cyberaguiar/CVE-2016-3088

Apache ActiveMQ Remote Code Execution Exploit

★ 5 · 2021-03-11
cl4ym0re/CVE-2016-3088

Apache ActiveMQ PUT RCE Scan

★ 4 · 2022-02-20
wood03mm/CVE-2016-3088
★ 0 · 2020-04-04
vonderchild/CVE-2016-3088
★ 0 · 2021-03-14
HeArtE4t3r/CVE-2016-3088

A Python-based Exploit Script for CVE-2016-3088

★ 0 · 2025-06-16
CVE-2021-39214
HIGHFRESH PoC
CVSS 8.1 HIGH CWE-444 Published 2021-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (10 hours, 59 minutes ago) Discovered 2026-10-09 03:16

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.

Show 1 repositories
CyberCTF/secdevlabs-golden-hat

secDevLabs Golden Hat Society: mitmproxy 5.3.0 request smuggling, CVE-2021-39214 (OWASP A06), run with Isoloom

★ 0 · 2026-10-09
CVE-2026-51994
NEWFRESH PoC
PoCs 1 ★ 3 Last push 2026-10-09 (11 hours ago) Discovered 2026-10-10 05:42

Fetching description from NVD…

Show 1 repositories
playb0t/mcp-remote-oauth-security

Forensic audit of mcp-remote: seven OAuth trust-boundary advisories, five CVE records (CVE-2026-51994/51995/51996/51997/52001). Server-selected request path (C…

★ 3 · 2026-10-09
CVE-2022-47966
FRESH PoCHOTMULTI PoC
PoCs 5 ★ 130 Last push 2026-10-09 (12 hours, 6 minutes ago)

Fetching description from NVD…

Show 5 repositories
horizon3ai/CVE-2022-47966

POC for CVE-2022-47966 affecting multiple ManageEngine products

★ 130 · 2023-01-19
vonahisec/CVE-2022-47966-Scan

Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.

★ 28 · 2026-10-09
sh4den/CVE-2022-47966

The manage engine mass loader for CVE-2022-47966

★ 7 · 2026-07-06
ACE-Responder/CVE-2022-47966_checker

Run on your ManageEngine server

★ 2 · 2023-01-23
shameem-testing/PoC-for-ME-SAML-Vulnerability

PoC for cve-2022-47966

★ 0 · 2023-01-19
< Prev Page 4 / 15 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.