Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
354PoC updated in 7 days
filters
504 results
PoCs 5
★ 316
Last push 2026-03-13 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
1NTheKut/CVE-2019-1003000_RCE-DETECTION
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
★ 4 · 2019-05-01
PoCs 4
★ 288
Last push 2026-03-11 (6 months, 4 weeks ago)
Fetching description from NVD…
Show 4 repositories
z-bool/Venom-JWT
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
★ 288 · 2025-08-12
PoCs 4
★ 214
Last push 2026-03-05 (7 months ago)
Fetching description from NVD…
Show 4 repositories
H4K6/CVE-2023-0179-PoC
针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。
★ 199 · 2023-03-16
PoCs 5
★ 200
Last push 2026-03-04 (7 months ago)
Fetching description from NVD…
Show 5 repositories
CrowTheArchfiend/RTCore64-probe
A tiny cpp program to test reading memory using a vulnerable RTCore64.sys driver/device (CVE-2019-16098). It tries to read a "secret" from its own memory usin…
★ 0 · 2026-03-04
PoCs 12
★ 100
Last push 2026-03-01 (7 months, 1 week ago)
Fetching description from NVD…
Show 8 of 12 repositories
aitorfirm/CVE-2025-25257
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
★ 1 · 2025-07-18
0xgh057r3c0n/CVE-2025-25257
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No l…
★ 1 · 2025-07-15
mrmtwoj/CVE-2025-25257
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
★ 1 · 2025-07-19
PoCs 1
★ 501
Last push 2026-02-23 (7 months, 2 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 7
★ 1414
Last push 2026-02-21 (7 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
knightswd/NoPacScan
NoPacScan is a CVE-2021-42287/CVE-2021-42278 Scanner,it scan for more domain controllers than other script
★ 87 · 2022-02-17
PoCs 13
★ 360
Last push 2026-02-06 (8 months ago)
Fetching description from NVD…
Show 8 of 13 repositories
BishopFox/pwn-pulse
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
★ 132 · 2020-01-15
cisagov/check-your-pulse
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
★ 28 · 2020-08-19
aqhmal/pulsexploit
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
★ 9 · 2020-04-25
es0/CVE-2019-11510_poc
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
★ 5 · 2019-08-27
PoCs 7
★ 205
Last push 2026-01-22 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
jduck/cve-2015-1538-1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
★ 205 · 2015-09-10
Tharana/vulnerability-exploitation
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
★ 3 · 2020-05-12
xsleaksiki/cve
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
★ 0 · 2026-01-22
PoCs 12
★ 164
Last push 2026-01-20 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 28
★ 658
Last push 2026-01-19 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 28 repositories
PoCs 19
★ 515
Last push 2026-01-19 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
shack2/javaserializetools
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
★ 515 · 2020-10-01
pimps/CVE-2019-2725
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
★ 52 · 2019-09-26
PoCs 2
★ 163
Last push 2026-01-08 (9 months ago)
Fetching description from NVD…
Show 2 repositories
PoCs 21
★ 2076
Last push 2026-01-07 (9 months ago)
Fetching description from NVD…
Show 8 of 21 repositories
0xn0ne/weblogicScanner
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、C…
★ 2076 · 2023-11-24
PoCs 14
★ 258
Last push 2025-12-29 (9 months, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 5
★ 102
Last push 2025-12-24 (9 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
0xf4n9x/CVE-2023-0669
CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrar…
★ 102 · 2024-04-16
Avento/CVE-2023-0669
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
★ 8 · 2023-07-07
PoCs 10
★ 463
Last push 2025-12-17 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 8
★ 205
Last push 2025-12-14 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 8 repositories
PoCs 6
★ 150
Last push 2025-12-12 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
mbanyamer/CVE-2025-11001---7-Zip
CVE-2025-11001 (CVSS 7.0) – 7-Zip < 25.00 Directory Traversal → RCE via crafted ZIP with symlink. Allows arbitrary file write when extracted as Administrator. …
★ 7 · 2025-11-22
PoCs 17
★ 373
Last push 2025-12-08 (10 months ago)
Fetching description from NVD…
Show 8 of 17 repositories
bao7uo/RAU_crypto
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
★ 179 · 2020-08-22
PoCs 12
★ 257
Last push 2025-12-02 (10 months, 1 week ago)
Fetching description from NVD…
Show 8 of 12 repositories
tijme/kernel-mii
Cobalt Strike (CS) Beacon Object File (BOF) foundation for kernel exploitation using CVE-2021-21551.
★ 85 · 2023-05-07
mathisvickie/CVE-2021-21551
arbitrary kernel read/write in dbutil_2_3.sys, Proof of Concept Local Privilege Escalation to nt authority/system
★ 60 · 2021-11-16
PoCs 4
★ 139
Last push 2025-12-01 (10 months, 1 week ago)
Fetching description from NVD…
Show 4 repositories
k8gege/PyLadon
Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894
★ 53 · 2020-12-08
PoCs 8
★ 132
Last push 2025-12-01 (10 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
jax7sec/S2-062
Apache Struts2 S2-062远程代码执行漏洞(CVE-2021-31805) 支持批量扫描漏洞及漏洞利用
★ 23 · 2022-04-15
PoCs 4
★ 113
Last push 2025-11-26 (10 months, 1 week ago)
Fetching description from NVD…
Show 4 repositories
PoCs 22
★ 131
Last push 2025-11-24 (10 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 22 repositories
s0md3v/Shiva
Improved DOS exploit for wordpress websites (CVE-2018-6389)
★ 131 · 2020-10-01
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.