Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

504 results

CVE-2025-66478
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 430 Last push 2026-10-09 (16 hours, 7 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

★ 430 · 2025-12-16
vercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

★ 401 · 2025-12-12
hackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.

★ 157 · 2025-12-10
abtonc/next-cve-2025-66478
★ 11 · 2025-12-08
khadafigans/React2Shell

React2Shell - CVE-2025-66478 RCE Exploit

★ 6 · 2026-02-12
wangxso/CVE-2025-66478-POC

CVE-2025-66478 Proof of Concept

★ 5 · 2025-12-17
abdozkaya/rsc-security-auditor

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…

★ 5 · 2025-12-13
strainxx/react2shell-honeypot

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

★ 4 · 2025-12-08
CVE-2025-49844
FRESH PoCHOTMULTI PoC
PoCs 19 ★ 345 Last push 2026-10-09 (16 hours, 14 minutes ago)

Fetching description from NVD…

Show 8 of 19 repositories
raminfp/redis_exploit

CVE-2025-49844 (RediShell)

★ 345 · 2025-10-07
dwisiswant0/CVE-2025-49844

CVE-2025-49844 – Redis Lua Parser Use-After-Free

★ 66 · 2025-10-07
saneki/cve-2025-49844

Proof-of-concept for CVE-2025-49844

★ 25 · 2025-11-20
lastvocher/redis-CVE-2025-49844
★ 14 · 2025-10-07
pedrorichil/CVE-2025-49844
★ 6 · 2025-10-08
Zain3311/CVE-2025-49844

🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.

★ 2 · 2026-10-09
MiclelsonCN/CVE-2025-49844_POC

CVE-2025-49844 POC

★ 2 · 2025-10-09
ksnnd32/redis_exploit

🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.

★ 1 · 2026-10-09
CVE-2025-32463
FRESH PoCHOTMULTI PoC
PoCs 69 ★ 529 Last push 2026-10-09 (16 hours, 19 minutes ago)

Fetching description from NVD…

Show 8 of 69 repositories
pr0v3rbs/CVE-2025-32463_chwoot

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

★ 529 · 2025-11-19
kh4sh3i/CVE-2025-32463

Local Privilege Escalation to Root via Sudo chroot in Linux

★ 476 · 2025-07-02
MohamedKarrab/CVE-2025-32463

Privilege escalation to root using sudo chroot, NO NEED for gcc installed.

★ 48 · 2025-10-06
K1tt3h/CVE-2025-32463-POC

CVE-2025-32463 Proof of concept

★ 30 · 2025-07-01
1xPwn/CVE-2025-32463

This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.

★ 26 · 2026-08-12
mirchr/CVE-2025-32463-sudo-chwoot

PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability

★ 25 · 2025-07-05
zinzloun/CVE-2025-32463

# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so

★ 14 · 2025-07-14
AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.

★ 11 · 2025-07-21
CVE-2026-43499
FRESH PoCHOTMULTI PoC
PoCs 158 ★ 1702 Last push 2026-10-09 (18 hours, 19 minutes ago)

Fetching description from NVD…

Show 8 of 158 repositories
YuKongA/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

★ 1702 · 2026-10-08
BuSung-dev/Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

★ 1381 · 2026-09-03
alex193a/Root-My-Pixel

Jailbreak supported Google Pixel phones with CVE-2026-43499

★ 429 · 2026-09-13
JoinChang/ghostlock-oneplus

GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader

★ 400 · 2026-09-17
x-spy/CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

★ 251 · 2026-07-15
hmascs/KSuRoot

KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…

★ 235 · 2026-10-02
MobiusM/CVE-2026-43499

CVE-2026-43499 PoC

★ 160 · 2026-06-27
Linuxoid-cn/CVE-2026-43499-Poc-Analysis

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

★ 108 · 2026-07-30
CVE-2021-44228
FRESH PoCHOTMULTI PoC
PoCs 456 ★ 3426 Last push 2026-10-09 (19 hours, 38 minutes ago)

Fetching description from NVD…

Show 8 of 456 repositories
fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

★ 3426 · 2022-11-23
kozmer/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

★ 1846 · 2024-02-12
christophetd/log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

★ 1141 · 2024-04-26
Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

★ 950 · 2022-01-15
logpresso/CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

★ 862 · 2022-04-07
f0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

★ 841 · 2023-06-13
mergebase/log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…

★ 640 · 2022-03-10
corretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

★ 497 · 2022-10-24
CVE-2026-20841
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 141 Last push 2026-10-09 (20 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
BTtea/CVE-2026-20841-PoC

PoC

★ 141 · 2026-02-11
patchpoint/CVE-2026-20841
★ 12 · 2026-02-12
atiilla/CVE-2026-20841
★ 5 · 2026-02-12
tangent65536/CVE-2026-20841

PoC for the "Windows Notepad RCE"

★ 2 · 2026-02-11
dogukankurnaz/CVE-2026-20841-PoC

CVE-2026-20841

★ 2 · 2026-02-12
hamzamalik3461/CVE-2026-20841

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

★ 1 · 2026-10-09
SecureWithUmer/CVE-2026-20841

PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…

★ 1 · 2026-02-12
CVE-2024-21762
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 150 Last push 2026-10-09 (20 hours, 43 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
h4x0r-dz/CVE-2024-21762

out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability

★ 150 · 2024-03-16
BishopFox/cve-2024-21762-check

Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762

★ 107 · 2024-07-05
r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check

Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)

★ 16 · 2025-06-29
d0rb/CVE-2024-21762

The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.

★ 12 · 2024-03-17
abrewer251/CVE-2024-21762_FortiNet_PoC

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

★ 4 · 2025-05-22
rdoix/cve-2024-21762-checker
★ 1 · 2024-06-20
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
deFr0ggy/CVE-2024-21762-Checker

This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…

★ 0 · 2024-03-25
CVE-2023-27997
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 134 Last push 2026-10-09 (20 hours, 43 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
BishopFox/CVE-2023-27997-check

Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing

★ 134 · 2024-05-08
lexfo/xortigate-cve-2023-27997

xortigate-cve-2023-27997

★ 63 · 2023-10-12
rio128128/CVE-2023-27997-POC

POC FortiOS SSL-VPN buffer overflow vulnerability

★ 27 · 2023-06-16
delsploit/CVE-2023-27997
★ 9 · 2023-10-12
TechinsightsPro/ShodanFortiOS

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

★ 2 · 2023-07-11
imbas007/CVE-2023-27997-Check
★ 1 · 2023-06-23
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
puckiestyle/cve-2023-27997
★ 0 · 2023-06-23
CVE-2022-40684
FRESH PoCHOTMULTI PoC
PoCs 31 ★ 358 Last push 2026-10-09 (20 hours, 43 minutes ago)

Fetching description from NVD…

Show 8 of 31 repositories
horizon3ai/CVE-2022-40684

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 358 · 2022-10-13
carlosevieira/CVE-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

★ 87 · 2022-10-13
arsolutioner/fortigate-belsen-leak

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

★ 87 · 2025-01-16
Filiplain/Fortinet-PoC-Auth-Bypass

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

★ 16 · 2023-04-02
kljunowsky/CVE-2022-40684-POC

Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 16 · 2023-01-21
TaroballzChen/CVE-2022-40684-metasploit-scanner

An authentication bypass using an alternate path or channel in Fortinet product

★ 14 · 2022-10-27
hughink/CVE-2022-40684
★ 11 · 2022-10-28
qingsiweisan/CVE-2022-40684
★ 9 · 2022-10-26
CVE-2018-13379
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 253 Last push 2026-10-09 (20 hours, 43 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
milo2012/CVE-2018-13379

CVE-2018-13379

★ 253 · 2019-08-14
Blazz3/cve2018-13379-nmap-script

CVE-2018-13379 Script for Nmap NSE.

★ 12 · 2020-09-09
Zeop-CyberSec/fortios_vpnssl_traversal_leak

This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download Forti…

★ 9 · 2021-02-26
B1anda0/CVE-2018-13379

Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本

★ 9 · 2020-12-14
0xHunter/FortiOS-Credentials-Disclosure

CVE-2018-13379 Exploit

★ 6 · 2019-09-24
k4nfr3/CVE-2018-13379-Fortinet

FortiVuln

★ 6 · 2020-11-19
jpiechowka/at-doom-fortigate

Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.

★ 5 · 2024-01-23
Zierax/CVE-2018-13379

CVE-2018-13379 fortiOS vulnerability POC

★ 2 · 2026-02-15
CVE-2023-32434
FRESH PoCHOT
PoCs 2 ★ 144 Last push 2026-10-09 (20 hours, 49 minutes ago)

Fetching description from NVD…

Show 2 repositories
alfiecg24/Trigon

Deterministic kernel exploit based on CVE-2023-32434.

★ 144 · 2026-05-14
rkrakesh524/oob_entry

oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙

★ 0 · 2026-10-09
CVE-2026-41089
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 231 Last push 2026-10-09 (21 hours, 54 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
0xABCD01/CVE-2026-41089

Netlogon and CLDAP vulnerability research with a proof of concept.

★ 231 · 2026-06-02
SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

★ 67 · 2026-09-11
HydraSoft/CVE-2026-41089-Netlogon-RCE

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …

★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…

★ 14 · 2026-06-04
hnytgl/CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

★ 13 · 2026-09-26
0xBlackash/CVE-2026-41089

CVE-2026-41089

★ 11 · 2026-06-05
ZeroDayVPN/CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…

★ 5 · 2026-09-29
opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

★ 1 · 2026-10-08
CVE-2019-7238
FRESH PoCHOTMULTI PoC
PoCs 7 ★ 154 Last push 2026-10-09 (22 hours, 1 minute ago)

Fetching description from NVD…

Show 7 repositories
mpgn/CVE-2019-7238

🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻

★ 154 · 2019-02-25
jas502n/CVE-2019-7238

Nexus Repository Manager 3 Remote Code Execution without authentication < 3.15.0

★ 85 · 2019-08-19
verctor/nexus_rce_CVE-2019-7238

Some debug notes and exploit(not blind)

★ 39 · 2019-07-28
magicming200/CVE-2019-7238_Nexus_RCE_Tool

CVE-2019-7238 Nexus RCE漏洞图形化一键检测工具。CVE-2019-7238 Nexus RCE Vul POC Tool.

★ 24 · 2020-01-15
DannyRavi/nmap-scripts

nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327

★ 2 · 2025-04-20
smallpiggy/CVE-2019-7238

RCE

★ 1 · 2021-05-20
CyberCTF/vulhub-nexus-cve-2019-7238

Vulhub nexus/CVE-2019-7238: Nexus Repository Manager 3 JEXL Injection RCE (CVE-2019-7238), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-3129
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 289 Last push 2026-10-09 (22 hours, 1 minute ago)

Fetching description from NVD…

Show 8 of 33 repositories
ambionics/laravel-exploits

Exploit for CVE-2021-3129

★ 289 · 2021-01-29
zhzyker/CVE-2021-3129

Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)

★ 166 · 2021-12-14
joshuavanderpoll/CVE-2021-3129

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

★ 158 · 2026-05-21
SNCKER/CVE-2021-3129

Laravel debug rce

★ 134 · 2021-01-24
nth347/CVE-2021-3129_exploit

Exploit for CVE-2021-3129

★ 69 · 2021-03-07
crisprss/Laravel_CVE-2021-3129_EXP
★ 18 · 2021-01-27
ajisai-babu/CVE-2021-3129-exp

Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp

★ 13 · 2023-03-04
CVE-2026-31431
FRESH PoCHOTMULTI PoC
PoCs 325 ★ 4074 Last push 2026-10-09 (22 hours, 6 minutes ago)

Fetching description from NVD…

Show 8 of 325 repositories
theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

★ 4074 · 2026-04-29
tgies/copy-fail-c

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

★ 445 · 2026-07-17
badsectorlabs/copyfail-go

A Go implementation of copyfail (CVE-2026-31431)

★ 360 · 2026-05-01
Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…

★ 191 · 2026-05-07
Sndav/CVE-2026-31431-Advanced-Exploit

CVE-2026-31431 纯文件利用

★ 111 · 2026-04-30
painoob/Copy-Fail-Exploit-CVE-2026-31431

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …

★ 109 · 2026-04-29
sgkdev/page_inject

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

★ 76 · 2026-05-06
Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)

★ 63 · 2026-05-03
CVE-2020-14882
FRESH PoCHOTMULTI PoC
PoCs 37 ★ 4291 Last push 2026-10-09 (22 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…

★ 4291 · 2021-04-04
jas502n/CVE-2020-14882

CVE-2020–14882、CVE-2020–14883

★ 288 · 2020-11-16
GGyao/CVE-2020-14882_ALL

CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。

★ 145 · 2022-03-29
s1kr10s/CVE-2020-14882

CVE-2020–14882 by Jang

★ 29 · 2020-10-29
NS-Sp4ce/CVE-2020-14882

CVE-2020-14882/14883/14750

★ 19 · 2020-11-04
XTeam-Wing/CVE-2020-14882

CVE-2020-14882 Weblogic-Exp

★ 17 · 2020-10-29
adm1in/CodeTest

CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。

★ 13 · 2020-12-29
GGyao/CVE-2020-14882_POC

CVE-2020-14882批量验证工具。

★ 12 · 2020-12-01
CVE-2017-10271
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 515 Last push 2026-10-09 (22 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
shack2/javaserializetools

Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。

★ 515 · 2020-10-01
c0mmand3rOpSec/CVE-2017-10271

WebLogic Exploit

★ 140 · 2018-07-13
kkirsche/CVE-2017-10271

Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)

★ 128 · 2022-09-16
7kbstorm/WebLogic_CNVD_C2019_48814

WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm

★ 115 · 2019-04-25
SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC

★ 105 · 2019-04-29
1337g/CVE-2017-10271

CVE-2017-10271 WEBLOGIC RCE (TESTED)

★ 39 · 2017-12-23
Cymmetria/weblogic_honeypot

WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …

★ 33 · 2020-04-25
Luffin/CVE-2017-10271

CVE-2017-10271 POC

★ 29 · 2018-01-10
CVE-2020-1938
FRESH PoCHOTMULTI PoC
PoCs 40 ★ 422 Last push 2026-10-09 (22 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
00theway/Ghostcat-CNVD-2020-10487

Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)

★ 422 · 2020-03-09
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner

Cnvd-2020-10487 / cve-2020-1938, scanner tool

★ 294 · 2021-11-26
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read

Tomcat的文件包含及文件读取漏洞利用POC

★ 57 · 2020-02-21
xindongzhuaizhuai/CVE-2020-1938
★ 45 · 2020-03-02
laolisafe/CVE-2020-1938

CVE-2020-1938漏洞复现

★ 38 · 2020-02-21
CVE-2017-12615
FRESH PoCHOTMULTI PoC
PoCs 18 ★ 295 Last push 2026-10-09 (22 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 18 repositories
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
breaktoprotect/CVE-2017-12615

POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.

★ 112 · 2022-10-09
mefulton/cve-2017-12615

just a python script for cve-2017-12615

★ 11 · 2017-10-01
xiaokp7/Tomcat_PUT_GUI_EXP

Tomcat PUT方法任意文件写入(CVE-2017-12615)exp

★ 11 · 2023-03-14
zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717

CVE-2017-12617 and CVE-2017-12615 for tomcat server

★ 6 · 2017-10-10
1337g/CVE-2017-12615

CVE-2017-12615 Tomcat RCE (TESTED)

★ 4 · 2017-12-26
wsg00d/cve-2017-12615

tomcat-put-cve-2017-12615

★ 3 · 2017-11-01
CVE-2023-27524
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 113 Last push 2026-10-09 (22 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 15 repositories
horizon3ai/CVE-2023-27524

Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset

★ 113 · 2023-09-09
Okaytc/Superset_auth_bypass_check

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

★ 11 · 2023-08-03
tardc/CVE-2023-27524

Apache Superset Auth Bypass (CVE-2023-27524)

★ 10 · 2023-05-09
ZZ-SOCMAP/CVE-2023-27524

Apache Superset Auth Bypass Vulnerability CVE-2023-27524.

★ 3 · 2023-04-27
Ap0dexMe0/CVE-2023-27524

Perform With Apache-SuperSet Leaked Token [CSRF]

★ 3 · 2023-07-24
Cappricio-Securities/CVE-2023-27524

Apache Superset - Authentication Bypass

★ 2 · 2024-06-24
karthi-the-hacker/CVE-2023-27524

Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)

★ 1 · 2024-05-11
CVE-2022-22965
FRESH PoCHOTMULTI PoC
PoCs 99 ★ 376 Last push 2026-10-09 (22 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 99 repositories
BobTheShoplifter/Spring4Shell-POC

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

★ 376 · 2022-11-09
reznok/Spring4Shell-POC

Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

★ 325 · 2022-08-04
tpt11fb/SpringVulScan

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

★ 155 · 2023-01-23
TheGejr/SpringShell

Spring4Shell - Spring Core RCE - CVE-2022-22965

★ 131 · 2022-04-04
zangcc/CVE-2022-22965-rexbb

CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。

★ 102 · 2023-11-14
alt3kx/CVE-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

★ 100 · 2022-04-07
SecNN/SpringFramework_CVE-2022-22965_RCE

SpringFramework 远程代码执行漏洞CVE-2022-22965

★ 72 · 2022-04-01
4nth0ny1130/spring4shell_behinder

CVE-2022-22965写入冰蝎webshell脚本

★ 62 · 2022-05-10
CVE-2022-22963
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 353 Last push 2026-10-09 (22 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
hktalent/spring-spel-0day-poc

spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963

★ 353 · 2023-03-05
dinosn/CVE-2022-22963

CVE-2022-22963 PoC

★ 116 · 2022-03-30
darryk10/CVE-2022-22963
★ 34 · 2022-04-15
J0ey17/CVE-2022-22963_Reverse-Shell-Exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vuln…

★ 24 · 2023-03-18
me2nuk/CVE-2022-22963

Spring Cloud Function Vulnerable Application / CVE-2022-22963

★ 19 · 2022-04-01
RanDengShiFu/CVE-2022-22963

CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit

★ 15 · 2022-03-30
kh4sh3i/Spring-CVE

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed …

★ 14 · 2022-03-31
Kirill89/CVE-2022-22963-PoC
★ 9 · 2022-03-30
CVE-2022-22947
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 223 Last push 2026-10-09 (22 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 62 repositories
lucksec/Spring-Cloud-Gateway-CVE-2022-22947

CVE-2022-22947

★ 223 · 2022-03-03
whwlsfb/cve-2022-22947-godzilla-memshell

CVE-2022-22947 注入Godzilla内存马

★ 208 · 2022-04-26
SecNN/CVE-2022-22947_Rce_Exp

Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947

★ 77 · 2022-11-14
tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway

CVE-2022-22947批量

★ 71 · 2022-03-04
0730Nophone/CVE-2022-22947-

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

★ 59 · 2022-05-16
crowsec-edtech/CVE-2022-22947

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

★ 37 · 2022-03-04
0x7eTeam/CVE-2022-22947

CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell

★ 35 · 2022-03-08
Tas9er/SpringCloudGatewayRCE

SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er

★ 27 · 2022-03-03
CVE-2016-4977
FRESH PoCHOT
PoCs 3 ★ 155 Last push 2026-10-09 (22 hours, 24 minutes ago)

Fetching description from NVD…

Show 3 repositories
tpt11fb/SpringVulScan

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

★ 155 · 2023-01-23
N0b1e6/CVE-2016-4977-POC
★ 0 · 2020-02-17
CyberCTF/vulhub-spring-cve-2016-4977

Vulhub spring/CVE-2016-4977: Spring Security OAuth2 Whitelabel SpEL RCE (CVE-2016-4977), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-17558
FRESH PoCHOTMULTI PoC
PoCs 6 ★ 4291 Last push 2026-10-09 (22 hours, 24 minutes ago)

Fetching description from NVD…

Show 6 repositories
zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…

★ 4291 · 2021-04-04
Ma1Dong/Solr_CVE-2019-17558

Solr_CVE-2019-17558

★ 2 · 2020-08-04
thelostworldFree/CVE-2019-17558_Solr_Vul_Tool

CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.

★ 1 · 2020-01-10
xkyrage/Exploit_CVE-2019-17558-RCE

Apache Solr 1.4 Injection to get a shell

★ 0 · 2020-12-15
CyberCTF/vulhub-solr-cve-2019-17558

Vulhub solr/CVE-2019-17558: Apache Solr Velocity Template RCE (CVE-2019-17558), run with Isoloom

★ 0 · 2026-10-09
Page 1 / 21 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.