Fetching description from NVD…
Show 1 repositories
DOS infinite-loop Vulnerability POC
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live355 results
Fetching description from NVD…
DOS infinite-loop Vulnerability POC
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison
Fetching description from NVD…
WP Import Export Lite < 3.9.33 - Authenticated Path Traversal to Sensitive File Disclosure
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
CVE-2021-38759 — Raspberry Pi OS Default Credentials Exploit
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Privilege Escalation vulnerability
WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
IDOR/BOLA in Events Manager <= 7.4.3 REST ticket update endpoint — CVE-2026-93661
Fetching description from NVD…
CVE-2026-13043 - Exploiting Panda / WatchGuard pskmad.sys authentication bypass for privileged IOCTL access, MSR disclosure and arbitrary process memory reads.
Fetching description from NVD…
CVE-2024-4367 & CVE-2024-34342 Proof of Concept
CVE-2024-4367 arbitrary js execution in pdf js
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…
YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script
Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
Fetching description from NVD…
CVE-2024-7971 OPPO Browser (Chromium 115) remote DoS PoC - OSRC verification only
Fetching description from NVD…
CVE-2026-81780 — Hash Form RCE
Fetching description from NVD…
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.
Android privilege escalation via an use-after-free in binder.c
Temproot for Bravia TV via CVE-2019-2215.
Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC
PoC for old Binder vulnerability (based on P0 exploit)
Fetching description from NVD…
checkm8 (CVE-2019-8900) for Apple A9, native to Linux — and a verdict system that never confuses 'this host cannot reset' with 'the exploit did not work'.
Fetching description from NVD…
( 0day ) Local Privilege Escalation in IObit Malware Fighter
Fetching description from NVD…
Zammad Session Leak to Remote Code Execution
Fetching description from NVD…
Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs
Fetching description from NVD…
Test whether a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492 EXP and Analysis write up
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)
CVE-2022-0492-Container-Escape
PoC for CVE-2022-0492
Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs
Fetching description from NVD…
Marimo Pre Authentication RCE
CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)
CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE (CVSS 9.3). Python & Nmap NSE detection scripts. Missing authentication on /terminal/ws WebSocket endpoint …
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability
Marimo Pre-Auth RCE
A proof-of-concept for CVE-2026-39987
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.
Benign, offline reproduction of CVE-2026-93355 — LiteLLM unverified-email JWT account takeover (runs LiteLLM's real code)
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable l…
CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)
Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional RCE (WP 4…
CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create,…
Unauthenticated RCE on Wordpress
XWP_RCE — CVE-2026-87902 Hacker Console
CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.
Proof of concept for vulnerability CVE-2026-87902 in Wordpress
Fetching description from NVD…
Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
Fetching description from NVD…
Test tool for CVE-2020-1472
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
Exploit for zerologon cve-2020-1472
Exploit Code for CVE-2020-1472 aka Zerologon
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
cve-2020-1472 复现利用及其exp
CVE-2020-1472 C++
Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB
Fetching description from NVD…
CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android
Dirty Cow exploit - CVE-2016-5195
PoC for Dirty COW (CVE-2016-5195)
A CVE-2016-5195 exploit example.
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
编译好的脏牛漏洞(CVE-2016-5195)EXP
Universal Android root tool based on CVE-2016-5195. Watch this space.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.