Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

504 results

PoCs 3 ★ 288 Last push 2025-08-12 (1 year, 1 month ago)

Fetching description from NVD…

Show 3 repositories
z-bool/Venom-JWT

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

★ 288 · 2025-08-12
CircuitSoul/poc-cve-2016-10555

Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)

★ 1 · 2021-06-14
scent2d/PoC-CVE-2016-10555

CVE-2016-10555 PoC code

★ 0 · 2022-01-03
PoCs 4 ★ 112 Last push 2025-08-05 (1 year, 2 months ago)

Fetching description from NVD…

Show 4 repositories
faisalfs10x/Webmin-CVE-2022-0824-revshell

Webmin <=1.984, CVE-2022-0824 Post-Auth Reverse Shell PoC

★ 112 · 2022-03-06
pizza-power/golang-webmin-CVE-2022-0824-revshell

Exploit POC for CVE-2022-0824

★ 3 · 2022-10-17
gokul-ramesh/WebminRCE-exploit

CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit

★ 0 · 2022-11-18
NUDTTAN91/Webmin-CVE-2022-0824-Enhanced-Exploit

Webmin CVE-2022-0824 增强版漏洞利用工具 - 支持命令执行和反向Shell双模式

★ 0 · 2025-08-05
PoCs 2 ★ 138 Last push 2025-08-01 (1 year, 2 months ago)

Fetching description from NVD…

Show 2 repositories
R00tkitSMM/CVE-2024-27804

POC for CVE-2024-27804

★ 138 · 2024-05-14
a0zhar/QuarkPoC

iOS Application w/Implementation of CVE-2024-27804

★ 1 · 2025-08-01
PoCs 2 ★ 108 Last push 2025-07-29 (1 year, 2 months ago)

Fetching description from NVD…

Show 2 repositories
saelo/jscpwn

PoC exploit for CVE-2016-4622

★ 108 · 2023-09-18
hdbreaker/WebKit-CVE-2016-4622

My journey through WebKit CVE-2016-4622 Exploitation process

★ 23 · 2025-07-29
PoCs 4 ★ 142 Last push 2025-07-28 (1 year, 2 months ago)

Fetching description from NVD…

Show 4 repositories
cpandya2909/CVE-2020-15778
★ 142 · 2023-03-27
Neko-chanQwQ/CVE-2020-15778-Exploit

Exploit for CVE-2020-15778(OpenSSH vul)

★ 38 · 2022-02-18
yifanzhg/CVE-2020-15778
★ 3 · 2023-09-27
drackyjr/CVE-2020-15778-SCP-Command-Injection-Check

This script is a safe and simple tool that helps system users, students, and administrators check if their SCP (Secure Copy) client is vulnerable to CVE-2020-1…

★ 2 · 2025-07-28
CVE-2025-32756
HOTMULTI PoC
PoCs 5 ★ 192 Last push 2025-07-23 (1 year, 2 months ago)

Fetching description from NVD…

Show 5 repositories
kn0x0x/CVE-2025-32756-POC

Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.

★ 192 · 2025-06-13
exfil0/CVE-2025-32756-POC

Designed for Demonstration of Deep Exploitation.

★ 4 · 2025-05-18
alm6no5/CVE-2025-32756-POC
★ 0 · 2025-06-09
becrevex/CVE-2025-32756

CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes

★ 0 · 2025-06-09
shan0ar/cve-2025-32756
★ 0 · 2025-07-23
CVE-2022-25845
HOTMULTI PoC
PoCs 5 ★ 109 Last push 2025-07-18 (1 year, 2 months ago)

Fetching description from NVD…

Show 5 repositories
luelueking/CVE-2022-25845-In-Spring

CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!

★ 109 · 2024-11-07
ph0ebus/CVE-2022-25845-In-Spring

exploit by python

★ 7 · 2024-12-01
nerowander/CVE-2022-25845-exploit
★ 1 · 2023-03-01
scabench/fastjson-tp1fn1

a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used

★ 0 · 2024-01-29
cuijiung/fastjson-CVE-2022-25845
★ 0 · 2025-07-18
PoCs 4 ★ 228 Last push 2025-07-11 (1 year, 2 months ago)

Fetching description from NVD…

Show 4 repositories
YYHYlh/Apache-Dubbo-CVE-2023-23638-exp

Apache Dubbo (CVE-2023-23638)漏洞利用的工程化实践

★ 228 · 2023-08-08
X1r0z/dubbo-rce

PoC of Apache Dubbo CVE-2023-23638

★ 34 · 2024-01-29
cuijiung/dubbo-CVE-2023-23638
★ 1 · 2025-07-11
P4x1s/CVE-2023-23638-Tools
★ 0 · 2023-06-08
PoCs 3 ★ 213 Last push 2025-07-10 (1 year, 3 months ago)

Fetching description from NVD…

Show 3 repositories
leesh3288/CVE-2025-32023

PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"

★ 213 · 2025-07-06
LordBheem/CVE-2025-32023

Exploit for CVE-2025-32023

★ 0 · 2025-07-10
44528zja/Blackash-CVE-2025-32023

CVE-2025-32023

★ 0 · 2025-07-09
PoCs 4 ★ 498 Last push 2025-06-25 (1 year, 3 months ago)

Fetching description from NVD…

Show 4 repositories
Bonfee/CVE-2022-0995

CVE-2022-0995 exploit

★ 498 · 2022-03-27
1nzag/CVE-2022-0995

CVE-2022-0995 exploit

★ 2 · 2024-01-03
AndreevSemen/CVE-2022-0995

Реализация средств повышения привилегий в Linux

★ 1 · 2023-03-10
A1b2rt/cve-2022-0995
★ 0 · 2025-06-25
CVE-2019-7304
HOTMULTI PoC
PoCs 5 ★ 681 Last push 2025-06-25 (1 year, 3 months ago)

Fetching description from NVD…

Show 5 repositories
initstring/dirty_sock

Linux privilege escalation exploit via snapd (CVE-2019-7304)

★ 681 · 2019-05-09
SecuritySi/CVE-2019-7304_DirtySock

Payload Generator

★ 6 · 2019-02-14
elvi7major/snap_priv_esc

Another implementation for linux privilege escalation exploit via snap(d) (CVE-2019-7304)

★ 1 · 2021-03-28
f4T1H21/dirty_sock

Local Privilege Escalation via snapd (CVE-2019-7304) Remastered PoC exploit

★ 1 · 2021-07-28
coby-nguyen/Document-Linux-Privilege-Escalation

Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.

★ 0 · 2025-06-25
PoCs 3 ★ 273 Last push 2025-06-06 (1 year, 4 months ago)

Fetching description from NVD…

Show 3 repositories
tarihub/blackjump

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

★ 273 · 2025-06-06
HolyGu/CVE-2023-42442
★ 39 · 2023-10-12
C1ph3rX13/CVE-2023-42442

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

★ 9 · 2023-10-31
PoCs 3 ★ 236 Last push 2025-05-25 (1 year, 4 months ago)

Fetching description from NVD…

Show 3 repositories
0vercl0k/CVE-2021-24086

Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.

★ 236 · 2021-04-15
lisinan988/CVE-2021-24086-exp
★ 1 · 2021-11-25
personnumber3377/windows_tcpip_fuzz

This is my attempt at fuzzing the tcpip.sys driver in windows via using scapy. This is inspired by this vulnerability here: https://doar-e.github.io/blog/2021/…

★ 0 · 2025-05-25
CVE-2020-14883
HOTMULTI PoC
PoCs 6 ★ 1073 Last push 2025-05-15 (1 year, 4 months ago)

Fetching description from NVD…

Show 6 repositories
1n7erface/PocList

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…

★ 1073 · 2023-05-11
murataydemir/CVE-2020-14883

[CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)

★ 13 · 2020-11-09
B1anda0/CVE-2020-14883

Weblogic 身份认证绕过漏洞批量检测脚本

★ 7 · 2020-11-11
fan1029/CVE-2020-14883EXP

用于对WebLogic(10.3.6.0.0 ;12.1.3.0.0 ;12.2.1.3.0; 12.2.1.4.0 ;14.1.1.0.0)进行验证及利用

★ 5 · 2021-01-26
Osyanina/westone-CVE-2020-14883-scanner

A vulnerability scanner that detects CVE-2020-14883 vulnerabilities.

★ 0 · 2021-03-20
amacloudobia/CVE-2020-14883

oracle weblogic

★ 0 · 2025-05-15
PoCs 1 ★ 131 Last push 2025-05-15 (1 year, 4 months ago)

Fetching description from NVD…

Show 1 repositories
mistymntncop/CVE-2023-3079
★ 131 · 2025-05-15
CVE-2022-46689
HOTMULTI PoC
PoCs 13 ★ 886 Last push 2025-05-12 (1 year, 4 months ago)

Fetching description from NVD…

Show 8 of 13 repositories
ginsudev/WDBFontOverwrite

Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.

★ 886 · 2023-08-02
zhuowei/MacDirtyCowDemo

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.

★ 410 · 2022-12-21
straight-tamago/FileSwitcherX

CVE-2022-46689

★ 151 · 2023-06-13
straight-tamago/NoCameraSound

CVE-2022-46689

★ 130 · 2025-05-12
mineek/FileManager

File Manager for CVE-2022-46689

★ 80 · 2023-01-02
straight-tamago/NoHomeBar

CVE-2022-46689

★ 72 · 2023-01-19
straight-tamago/DockTransparent

CVE-2022-46689

★ 56 · 2023-01-19
bomberfish/Mandela-Legacy

iOS customization app powered by CVE-2022-46689

★ 23 · 2023-02-12
PoCs 2 ★ 104 Last push 2025-04-07 (1 year, 6 months ago)

Fetching description from NVD…

Show 2 repositories
jas502n/CVE-2019-12409

Apache Solr RCE (ENABLE_REMOTE_JMX_OPTS="true")

★ 104 · 2019-11-19
mbadanoiu/CVE-2019-12409

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

★ 0 · 2025-04-07
PoCs 2 ★ 247 Last push 2025-03-31 (1 year, 6 months ago)

Fetching description from NVD…

Show 2 repositories
hakaioffsec/IngressNightmare-PoC

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

★ 247 · 2025-03-26
lufeirider/IngressNightmare-PoC

IngressNightmare-PoC: (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) PoC ,One-click script 。 一键脚本

★ 9 · 2025-03-31
PoCs 4 ★ 194 Last push 2025-03-28 (1 year, 6 months ago)

Fetching description from NVD…

Show 4 repositories
euphrat1ca/CVE-2020-0618

SQL Server Reporting Services(CVE-2020-0618)中的RCE

★ 194 · 2020-02-15
wortell/cve-2020-0618

CVE-2020-0618 Honeypot

★ 30 · 2020-03-03
itstarsec/CVE-2020-0618

Melissa

★ 2 · 2022-05-13
PoCs 2 ★ 136 Last push 2025-03-27 (1 year, 6 months ago)

Fetching description from NVD…

Show 2 repositories
PeterGabaldon/CVE-2024-7479_CVE-2024-7481

TeamViewer User to Kernel Elevation of Privilege PoC. CVE-2024-7479 and CVE-2024-7481. ZDI-24-1289 and ZDI-24-1290. TV-2024-1006.

★ 136 · 2024-12-22
fortra/CVE-2024-7479

Proof of concept for CVE-2024-7479

★ 8 · 2025-03-27
PoCs 3 ★ 146 Last push 2025-02-26 (1 year, 7 months ago)

Fetching description from NVD…

Show 3 repositories
milo2012/CVE-2018-13382

CVE-2018-13382

★ 146 · 2019-08-13
tumikoto/Exploit-FortinetMagicBackdoor

PoC for CVE-2018-13382, never successfully tested so swim at your own risk

★ 1 · 2021-04-28
cojoben/CVE-2018-13382
★ 0 · 2025-02-26
PoCs 3 ★ 105 Last push 2025-02-12 (1 year, 7 months ago)

Fetching description from NVD…

Show 3 repositories
bjrjk/CVE-2022-4262

Full Chain Analysis of CVE-2022-4262, a non-trivial feedback slot type confusion in V8.

★ 105 · 2025-02-12
mistymntncop/CVE-2022-4262
★ 58 · 2024-01-29
quangnh89/CVE-2022-4262
★ 0 · 2024-02-11
CVE-2021-26084
HOTMULTI PoC
PoCs 35 ★ 316 Last push 2025-02-11 (1 year, 7 months ago)

Fetching description from NVD…

Show 8 of 35 repositories
hev0x/CVE-2021-26084_Confluence

Confluence Server Webwork OGNL injection

★ 316 · 2025-02-11
0xf4n9x/CVE-2021-26084

CVE-2021-26084 Remote Code Execution on Confluence Servers

★ 72 · 2022-02-10
alt3kx/CVE-2021-26084_PoC
★ 53 · 2021-09-01
dinhbaouit/CVE-2021-26084
★ 53 · 2021-09-01
1ZRR4H/CVE-2021-26084

Atlassian Confluence CVE-2021-26084 one-liner mass checker

★ 30 · 2021-09-07
crowsec-edtech/CVE-2021-26084

CVE-2021-26084 - Confluence Pre-Auth RCE | OGNL injection

★ 21 · 2021-09-01
ZZ-SOCMAP/CVE-2021-26084

POC of CVE-2021-26084, which is Atlassian Confluence Server OGNL(Object-Graph Navigation Language) Pre-Auth RCE Injection Vulneralibity.

★ 9 · 2022-01-14
Vulnmachines/Confluence_CVE-2021-26084

Remote Code Execution on Confluence Servers : CVE-2021-26084

★ 8 · 2022-07-29
CVE-2014-4210
HOTMULTI PoC
PoCs 5 ★ 2076 Last push 2025-02-09 (1 year, 8 months ago)

Fetching description from NVD…

Show 5 repositories
0xn0ne/weblogicScanner

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、C…

★ 2076 · 2023-11-24
NoneNotNull/SSRFX

CVE-2014-4210+Redis未授权访问

★ 98 · 2017-03-10
NHPT/WebLogic-SSRF_CVE-2014-4210

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

★ 11 · 2020-11-20
unmanarc/CVE-2014-4210-SSRF-PORTSCANNER-POC

CVE-2014-4210 SSRF PORTSCANNER PoC

★ 3 · 2020-07-21
PoCs 1 ★ 147 Last push 2025-01-13 (1 year, 8 months ago)

Fetching description from NVD…

Show 1 repositories
passtheticket/CVE-2024-38200

CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability

★ 147 · 2025-01-13
< Prev Page 12 / 21 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.