Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
360PoC updated in 7 days
filters
360 results
PoCs 12
★ 231
Last push 2026-10-09 (23 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
HydraSoft/CVE-2026-41089-Netlogon-RCE
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …
★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…
★ 14 · 2026-06-04
hnytgl/CVE-2026-41089
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
★ 13 · 2026-09-26
ZeroDayVPN/CVE-2026-41089-Netlogon
🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…
★ 5 · 2026-09-29
PoCs 4
★ 16
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 4 repositories
shinthink/CVE-2026-57827
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
★ 16 · 2026-07-29
Candisexterior171/CVE-2026-57827
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
★ 0 · 2026-10-09
PoCs 11
★ 7
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 of 11 repositories
everest90909/YellowKey-WinRE-Remediation
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…
★ 1 · 2026-05-21
PoCs 8
★ 13
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 repositories
PoCs 40
★ 12
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …
★ 12 · 2026-06-14
luiskrnr/exploit-CVE-2026-23744
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…
★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …
★ 3 · 2026-08-11
ctzisme/CVE-2026-23744
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
★ 1 · 2026-03-26
PoCs 325
★ 4074
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 of 325 repositories
tgies/copy-fail-c
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
★ 445 · 2026-07-17
painoob/Copy-Fail-Exploit-CVE-2026-31431
Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …
★ 109 · 2026-04-29
sgkdev/page_inject
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
★ 76 · 2026-05-06
PoCs 3
★ 1
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 3 repositories
Jvr2022/CVE-2026-31802
PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.
★ 1 · 2026-03-14
PoCs 40
★ 35
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 of 40 repositories
Black1hp/mongobleed-scanner
MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool
★ 35 · 2025-12-28
cybertechajju/CVE-2025-14847_Expolit
a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…
★ 34 · 2025-12-27
PoCs 7
★ 4
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 7 repositories
Nikopmpm/nikopmpm.github.io
🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.
★ 0 · 2026-01-09
PoCs 462
★ 2453
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 8 of 462 repositories
mrknow001/RSC_Detector
Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.
★ 588 · 2025-12-05
emredavut/CVE-2025-55182
RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478
★ 313 · 2025-12-06
PoCs 5
★ 5
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 5 repositories
rxerium/CVE-2025-26466
The OpenSSH client and server are vulnerable to a pre-authentication DoS attack between versions 9.5p1 to 9.9p1 (inclusive) that causes memory and CPU consump…
★ 5 · 2025-10-14
PoCs 3
★ 9
Last push 2026-10-09 (1 day ago)
Fetching description from NVD…
Show 3 repositories
PoCs 1
★ 0
Last push 2026-10-09 (1 day ago)
Discovered 2026-10-09 14:08
Fetching description from NVD…
Show 1 repositories
PoCs 3
★ 2
Last push 2026-10-09 (1 day, 1 hour ago)
Fetching description from NVD…
Show 3 repositories
CVSS 7.5 HIGH
CWE-285
Published 2025-09-16
PoCs 1
★ 0
Last push 2026-10-09 (1 day, 1 hour ago)
Discovered 2026-10-09 14:08
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.
Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.
You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces.
This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Show 1 repositories
PoCs 3
★ 0
Last push 2026-10-09 (1 day, 1 hour ago)
Fetching description from NVD…
Show 3 repositories
suominen/tunderflow
Tracking TUNderflow (CVE-2026-81000), the Linux kernel TUN/TAP receive-headroom underflow
★ 0 · 2026-10-09
CVSS 8.8 HIGH
CWE-415
Published 2021-06-07
PoCs 1
★ 0
Last push 2026-10-09 (1 day, 2 hours ago)
Discovered 2026-10-09 03:16
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-09 (1 day, 3 hours ago)
Discovered 2026-10-09 14:08
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 1
Last push 2026-10-09 (1 day, 3 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 6
Last push 2026-10-09 (1 day, 3 hours ago)
Fetching description from NVD…
Show 2 repositories
tc4dy/CVE-2026-53921-PoC-Exploit
CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (I…
★ 6 · 2026-10-09
PoCs 4
★ 1
Last push 2026-10-09 (1 day, 4 hours ago)
Fetching description from NVD…
Show 4 repositories
HackSpeak/CVE-2026-23479
Redis CVE-2026-23479 UAF RCE vulnerability checker mirror — pduggusa, MIT; for authorized security testing
★ 1 · 2026-08-19
pduggusa/redis-cve-2026-23479-check
Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By Dugga…
★ 0 · 2026-06-04
PoCs 4
★ 42
Last push 2026-10-09 (1 day, 5 hours ago)
Fetching description from NVD…
Show 4 repositories
PoCs 4
★ 212
Last push 2026-10-09 (1 day, 5 hours ago)
Fetching description from NVD…
Show 4 repositories
PoCs 5
★ 4
Last push 2026-10-09 (1 day, 6 hours ago)
Fetching description from NVD…
Show 5 repositories
chu0119/vc-strike
VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only…
★ 1 · 2026-10-03
CVSS 9.3 CRITICAL
CWE-200, CWE-306, CWE-400
Published 2026-06-23
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 8 hours ago)
Discovered 2026-10-09 03:16
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.