Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
CVE-2025-41249
CVE-2024-36774
CVE-2022-21812
8 contacts in last 24h
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
504 results
PoCs 26
★ 430
Last push 2026-10-09 (16 hours, 7 minutes ago)
Fetching description from NVD…
Show 8 of 26 repositories
abdozkaya/rsc-security-auditor
🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…
★ 5 · 2025-12-13
PoCs 19
★ 345
Last push 2026-10-09 (16 hours, 14 minutes ago)
Fetching description from NVD…
Show 8 of 19 repositories
Zain3311/CVE-2025-49844
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
★ 2 · 2026-10-09
ksnnd32/redis_exploit
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
★ 1 · 2026-10-09
PoCs 69
★ 529
Last push 2026-10-09 (16 hours, 19 minutes ago)
Fetching description from NVD…
Show 8 of 69 repositories
1xPwn/CVE-2025-32463
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
★ 26 · 2026-08-12
PoCs 158
★ 1702
Last push 2026-10-09 (18 hours, 19 minutes ago)
Fetching description from NVD…
Show 8 of 158 repositories
hmascs/KSuRoot
KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…
★ 235 · 2026-10-02
PoCs 456
★ 3426
Last push 2026-10-09 (19 hours, 38 minutes ago)
Fetching description from NVD…
Show 8 of 456 repositories
fullhunt/log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
★ 3426 · 2022-11-23
f0ng/log4j2burpscanner
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
★ 841 · 2023-06-13
mergebase/log4j-detector
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…
★ 640 · 2022-03-10
PoCs 14
★ 141
Last push 2026-10-09 (20 hours, 24 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
SecureWithUmer/CVE-2026-20841
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…
★ 1 · 2026-02-12
PoCs 13
★ 150
Last push 2026-10-09 (20 hours, 43 minutes ago)
Fetching description from NVD…
Show 8 of 13 repositories
d0rb/CVE-2024-21762
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
★ 12 · 2024-03-17
deFr0ggy/CVE-2024-21762-Checker
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…
★ 0 · 2024-03-25
PoCs 12
★ 134
Last push 2026-10-09 (20 hours, 43 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 31
★ 358
Last push 2026-10-09 (20 hours, 43 minutes ago)
Fetching description from NVD…
Show 8 of 31 repositories
horizon3ai/CVE-2022-40684
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
★ 358 · 2022-10-13
PoCs 14
★ 253
Last push 2026-10-09 (20 hours, 43 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
jpiechowka/at-doom-fortigate
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
★ 5 · 2024-01-23
PoCs 2
★ 144
Last push 2026-10-09 (20 hours, 49 minutes ago)
Fetching description from NVD…
Show 2 repositories
rkrakesh524/oob_entry
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
★ 0 · 2026-10-09
PoCs 12
★ 231
Last push 2026-10-09 (21 hours, 54 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
HydraSoft/CVE-2026-41089-Netlogon-RCE
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …
★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…
★ 14 · 2026-06-04
hnytgl/CVE-2026-41089
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
★ 13 · 2026-09-26
ZeroDayVPN/CVE-2026-41089-Netlogon
🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…
★ 5 · 2026-09-29
PoCs 7
★ 154
Last push 2026-10-09 (22 hours, 1 minute ago)
Fetching description from NVD…
Show 7 repositories
mpgn/CVE-2019-7238
🐱💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱💻
★ 154 · 2019-02-25
PoCs 33
★ 289
Last push 2026-10-09 (22 hours, 1 minute ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 325
★ 4074
Last push 2026-10-09 (22 hours, 6 minutes ago)
Fetching description from NVD…
Show 8 of 325 repositories
tgies/copy-fail-c
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
★ 445 · 2026-07-17
painoob/Copy-Fail-Exploit-CVE-2026-31431
Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …
★ 109 · 2026-04-29
sgkdev/page_inject
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
★ 76 · 2026-05-06
PoCs 37
★ 4291
Last push 2026-10-09 (22 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 37 repositories
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…
★ 4291 · 2021-04-04
adm1in/CodeTest
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。
★ 13 · 2020-12-29
PoCs 30
★ 515
Last push 2026-10-09 (22 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 30 repositories
shack2/javaserializetools
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
★ 515 · 2020-10-01
Cymmetria/weblogic_honeypot
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …
★ 33 · 2020-04-25
PoCs 40
★ 422
Last push 2026-10-09 (22 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
tpt11fb/AttackTomcat
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
★ 257 · 2022-11-15
PoCs 18
★ 295
Last push 2026-10-09 (22 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 18 repositories
tpt11fb/AttackTomcat
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
★ 257 · 2022-11-15
PoCs 15
★ 113
Last push 2026-10-09 (22 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 99
★ 376
Last push 2026-10-09 (22 hours, 24 minutes ago)
Fetching description from NVD…
Show 8 of 99 repositories
tpt11fb/SpringVulScan
burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977
★ 155 · 2023-01-23
PoCs 30
★ 353
Last push 2026-10-09 (22 hours, 24 minutes ago)
Fetching description from NVD…
Show 8 of 30 repositories
hktalent/spring-spel-0day-poc
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
★ 353 · 2023-03-05
kh4sh3i/Spring-CVE
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed …
★ 14 · 2022-03-31
PoCs 62
★ 223
Last push 2026-10-09 (22 hours, 24 minutes ago)
Fetching description from NVD…
Show 8 of 62 repositories
PoCs 3
★ 155
Last push 2026-10-09 (22 hours, 24 minutes ago)
Fetching description from NVD…
Show 3 repositories
tpt11fb/SpringVulScan
burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977
★ 155 · 2023-01-23
PoCs 6
★ 4291
Last push 2026-10-09 (22 hours, 24 minutes ago)
Fetching description from NVD…
Show 6 repositories
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…
★ 4291 · 2021-04-04
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.