Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
357PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

504 results

CVE-2024-43044
HOTMULTI PoC
PoCs 5 ★ 184 Last push 2025-01-12 (1 year, 8 months ago)

Fetching description from NVD…

Show 5 repositories
convisolabs/CVE-2024-43044-jenkins

Exploit for the vulnerability CVE-2024-43044 in Jenkins

★ 184 · 2024-10-02
HwMex0/CVE-2024-43044

The script checks Jenkins endpoints for CVE-2024-43044 by retrieving the Jenkins version from the innstance and comparing it against known vulnerable version r…

★ 20 · 2024-08-08
v9d0g/CVE-2024-43044-POC

CVE-2024-43044的利用方式

★ 19 · 2024-08-13
jenkinsci-cert/SECURITY-3430

This repository provides a workaround preventing exploitation of SECURITY-3430 / CVE-2024-43044

★ 2 · 2024-08-12
PoCs 1 ★ 190 Last push 2025-01-04 (1 year, 9 months ago)

Fetching description from NVD…

Show 1 repositories
Aether-0/CVE-2024-12986
★ 190 · 2025-01-04
PoCs 1 ★ 106 Last push 2024-12-26 (1 year, 9 months ago)

Fetching description from NVD…

Show 1 repositories
keowu/BadRentdrv2

A vulnerable driver exploited by me (BYOVD) that is capable of terminating several EDRs and antivirus software in the market, rendering them ineffective, worki…

★ 106 · 2024-12-26
CVE-2017-12617
HOTMULTI PoC
PoCs 10 ★ 400 Last push 2024-12-16 (1 year, 9 months ago)

Fetching description from NVD…

Show 8 of 10 repositories
cyberheartmi9/CVE-2017-12617

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

★ 400 · 2017-10-11
LongWayHomie/CVE-2017-12617

CVE-2017-12617 is a critical vulnerability leading to Remote Code Execution (RCE) in Apache Tomcat.

★ 6 · 2021-12-11
ygouzerh/CVE-2017-12617

Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018

★ 2 · 2019-01-14
tyranteye666/tomcat-cve-2017-12617

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution for Python3

★ 1 · 2021-07-03
jptr218/tc_hack

An implementation of CVE-2017-12617

★ 1 · 2021-07-27
devcoinfet/CVE-2017-12617

Code put together from a few peoples ideas credit given don't use maliciously please

★ 0 · 2018-02-09
qiantu88/CVE-2017-12617
★ 0 · 2018-12-19
scirusvulgaris/CVE-2017-12617
★ 0 · 2024-06-28
CVE-2019-12725
HOTMULTI PoC
PoCs 5 ★ 178 Last push 2024-12-16 (1 year, 9 months ago)

Fetching description from NVD…

Show 5 repositories
sma11new/PocList

漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、Show…

★ 178 · 2021-11-21
hev0x/CVE-2019-12725-Command-Injection

ZeroShell 3.9.0 Remote Command Injection

★ 2 · 2021-06-14
givemefivw/CVE-2019-12725

CVE-2019-12725 ZeroShell 远程命令执行漏洞

★ 1 · 2021-07-02
gougou123-hash/CVE-2019-12725

ZeroShell命令执行漏洞批量扫描poc+exp

★ 0 · 2021-06-29
CVE-2020-0041
HOTMULTI PoC
PoCs 5 ★ 258 Last push 2024-12-14 (1 year, 9 months ago)

Fetching description from NVD…

Show 5 repositories
bluefrostsecurity/CVE-2020-0041

Exploits for Android Binder bug CVE-2020-0041

★ 258 · 2020-04-08
j4nn/CVE-2020-0041
★ 63 · 2024-12-14
jcalabres/root-exploit-pixel3

Adapted CVE-2020-0041 root exploit for Pixel 3

★ 14 · 2023-08-29
vaginessa/CVE-2020-0041-Pixel-3a

Local privilege escalation exploit for Android Binder bug CVE-2020-0041 (Pixel 3a)

★ 9 · 2021-04-15
koharin/CVE-2020-0041
★ 1 · 2021-10-15
CVE-2022-23131
HOTMULTI PoC
PoCs 20 ★ 155 Last push 2024-11-30 (1 year, 10 months ago)

Fetching description from NVD…

Show 8 of 20 repositories
Mr-xn/cve-2022-23131

cve-2022-23131 zabbix-saml-bypass-exp

★ 155 · 2024-08-11
jweny/CVE-2022-23131

cve-2022-23131 exp

★ 95 · 2022-02-21
L0ading-x/cve-2022-23131

cve-2022-23131

★ 29 · 2022-02-22
kh4sh3i/CVE-2022-23131

Zabbix - SAML SSO Authentication Bypass

★ 15 · 2022-03-31
Kazaf6s/CVE-2022-23131

CVE-2022-23131漏洞利用工具开箱即用。

★ 11 · 2022-04-02
random-robbie/cve-2022-23131-exp

Zabbix SSO Bypass

★ 8 · 2022-02-23
SCAMagic/CVE-2022-23131poc-exp-zabbix-

CVE-2022-23131漏洞批量检测与利用脚本

★ 8 · 2022-07-22
fork-bombed/CVE-2022-23131

CVE-2022-23131 Zabbix Server SAML authentication exploit

★ 4 · 2024-09-18
CVE-2024-21683
HOTMULTI PoC
PoCs 5 ★ 128 Last push 2024-11-29 (1 year, 10 months ago)

Fetching description from NVD…

Show 5 repositories
W01fh4cker/CVE-2024-21683-RCE

CVE-2024-21683 Confluence Post Auth RCE

★ 128 · 2024-05-27
absholi7ly/-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server

This vulnerability could allow an attacker to take complete control of a vulnerable Confluence server. This could allow the attacker to steal data, modify data…

★ 11 · 2024-05-24
r00t7oo2jm/-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server

This vulnerability allows an unauthenticated attacker to remotely execute arbitrary code on a vulnerable Confluence server. The vulnerability exists due to an …

★ 2 · 2024-05-22
phucrio/CVE-2024-21683-RCE
★ 1 · 2024-05-27
r3db34rdh4x/cve-2024-21683-rce

CVE-2024-21683 Confluence Post Auth RCE

★ 0 · 2024-11-29
PoCs 4 ★ 202 Last push 2024-11-18 (1 year, 10 months ago)

Fetching description from NVD…

Show 4 repositories
po6ix/POC-for-CVE-2023-41993
★ 202 · 2024-03-08
hrtowii/cve-2023-41993-test

testing poc

★ 16 · 2023-10-18
0x06060606/CVE-2023-41993

CVE-2023-41993

★ 5 · 2024-11-18
J3Ss0u/CVE-2023-41993
★ 0 · 2024-02-28
PoCs 3 ★ 641 Last push 2024-11-15 (1 year, 10 months ago)

Fetching description from NVD…

Show 3 repositories
YagamiiLight/Cerberus

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,…

★ 641 · 2020-01-05
MikeTheHash/CVE-2018-5955

An exploit for CVE-2018-5955 GitStack 2.3.10 Unauthenticated RCE

★ 10 · 2024-11-15
QianliZLP/GitStackRCE

GitStackRCE漏洞(CVE-2018-5955)EXP

★ 0 · 2018-09-11
PoCs 1 ★ 119 Last push 2024-11-06 (1 year, 11 months ago)

Fetching description from NVD…

Show 1 repositories
cbayet/Exploit-CVE-2017-6008

Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.

★ 119 · 2024-11-06
PoCs 1 ★ 199 Last push 2024-11-05 (1 year, 11 months ago)

Fetching description from NVD…

Show 1 repositories
canyie/MagiskEoP

Exploit and writeup for installed app to root privilege escalation through CVE-2024-48336 (Magisk Bug #8279), Privileges Escalation / Arbitrary Code Execution …

★ 199 · 2024-11-05
PoCs 1 ★ 115 Last push 2024-10-26 (1 year, 11 months ago)

Fetching description from NVD…

Show 1 repositories
dipakpanchal05/CVE-2022-23808

phpMyAdmin XSS

★ 115 · 2024-10-26
PoCs 1 ★ 215 Last push 2024-10-17 (1 year, 11 months ago)

Fetching description from NVD…

Show 1 repositories
Markakd/bad_io_uring

Android kernel exploitation for CVE-2022-20409

★ 215 · 2024-10-17
PoCs 1 ★ 106 Last push 2024-10-17 (1 year, 11 months ago)

Fetching description from NVD…

Show 1 repositories
Dor00tkit/CVE-2024-30090

CVE-2024-30090 - LPE PoC

★ 106 · 2024-10-17
CVE-2021-31166
HOTMULTI PoC
PoCs 11 ★ 823 Last push 2024-10-17 (1 year, 11 months ago)

Fetching description from NVD…

Show 8 of 11 repositories
0vercl0k/CVE-2021-31166

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

★ 823 · 2021-06-12
ZZ-SOCMAP/CVE-2021-31166

Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166

★ 19 · 2021-11-04
corelight/CVE-2021-31166

HTTP Protocol Stack CVE-2021-31166

★ 12 · 2024-10-17
zha0gongz1/CVE-2021-31166

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system …

★ 8 · 2021-05-17
0xmaximus/Home-Demolisher

PoC for CVE-2021-31166 and CVE-2022-21907

★ 8 · 2022-12-08
y0g3sh-99/CVE-2021-31166-Exploit

Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)

★ 7 · 2021-07-03
mauricelambert/CVE-2021-31166

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

★ 6 · 2022-03-16
zecopro/CVE-2021-31166

simple bash script for exploit CVE-2021-31166

★ 5 · 2021-05-19
CVE-2022-1015
HOTMULTI PoC
PoCs 9 ★ 209 Last push 2024-10-15 (1 year, 11 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
pqlx/CVE-2022-1015

Local privilege escalation PoC for Linux kernel CVE-2022-1015

★ 209 · 2022-04-03
ysanatomic/CVE-2022-1015

A write-up and LPE PoC of an OOB read and write vulnerability in the Linux Kernel.

★ 4 · 2022-11-12
pivik271/CVE-2022-1015
★ 1 · 2023-03-22
more-kohii/CVE-2022-1015

Linux Kernel 1-Day Analysis & Exploitation

★ 1 · 2023-08-08
zanezhub/CVE-2022-1015-1016

Traducción al español de los CVE-2022-1015 y 1016 descubiertos y documentados por David.

★ 0 · 2022-04-14
wlswotmd/CVE-2022-1015
★ 0 · 2023-04-26
delsploit/CVE-2022-1015
★ 0 · 2023-03-06
0range1337/CVE-2022-1015
★ 0 · 2024-03-18
CVE-2020-6287
HOTMULTI PoC
PoCs 7 ★ 223 Last push 2024-10-07 (2 years ago)

Fetching description from NVD…

Show 7 repositories
chipik/SAP_RECON

PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)

★ 223 · 2020-09-29
duc-nt/CVE-2020-6287-exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR m…

★ 96 · 2020-07-21
murataydemir/CVE-2020-6287

[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)

★ 13 · 2020-09-18
ynsmroztas/CVE-2020-6287-Sap-Add-User

sap netweaver portal add user administrator

★ 1 · 2020-07-22
dylvie/CVE-2020-6287_SAP-NetWeaver-bypass-auth

Automated Exploit for CVE-2020-6287

★ 1 · 2024-10-07
qmakake/SAP_CVE-2020-6287_find_mandate

Checker help to verify created account or find it's mandat

★ 0 · 2023-04-07
CVE-2020-9484
HOTMULTI PoC
PoCs 17 ★ 214 Last push 2024-10-06 (2 years ago)

Fetching description from NVD…

Show 8 of 17 repositories
threedr3am/tomcat-cluster-session-sync-exp

tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞,这个是sessi…

★ 214 · 2020-05-19
masahiro331/CVE-2020-9484
★ 126 · 2021-10-28
IdealDreamLast/CVE-2020-9484

用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞

★ 52 · 2020-05-21
PenTestical/CVE-2020-9484
★ 35 · 2022-04-16
0dayCTF/CVE-2020-9484

Remake of CVE-2020-9484 by Pentestical

★ 26 · 2024-09-16
d3fudd/CVE-2020-9484_Exploit

Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE

★ 17 · 2023-04-17
VICXOR/CVE-2020-9484

POC for CVE-2020-9484

★ 13 · 2021-02-10
anjai94/CVE-2020-9484-exploit
★ 6 · 2020-09-05
PoCs 2 ★ 135 Last push 2024-10-05 (2 years ago)

Fetching description from NVD…

Show 2 repositories
mrmtwoj/apache-vulnerability-testing

Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , …

★ 135 · 2024-10-05
Abdurahmon3236/CVE-2024-38472
★ 4 · 2024-08-03
PoCs 1 ★ 135 Last push 2024-10-05 (2 years ago)

Fetching description from NVD…

Show 1 repositories
mrmtwoj/apache-vulnerability-testing

Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , …

★ 135 · 2024-10-05
CVE-2022-26809
HOTMULTI PoC
PoCs 10 ★ 409 Last push 2024-09-16 (2 years ago)

Fetching description from NVD…

Show 8 of 10 repositories
fuckjsonp/FuckJsonp-RCE-CVE-2022-26809-SQL-XSS-FuckJsonp

警惕 一种针对红队的新型溯源手段!

★ 409 · 2022-07-27
s1ckb017/PoC-CVE-2022-26809

PoC for CVE-2022-26809, analisys and considerations are shown in the github.io.

★ 106 · 2022-06-18
yuanLink/CVE-2022-26809
★ 61 · 2022-05-25
corelight/cve-2022-26809

Detects attempts and successful exploitation of CVE-2022-26809

★ 32 · 2024-09-16
websecnl/CVE-2022-26809

Remote Code Execution Exploit in the RPC Library

★ 27 · 2022-04-19
sherlocksecurity/Microsoft-CVE-2022-26809-The-Little-Boy

The poc for CVE-2022-26809 RCE via RPC will be updated here.

★ 19 · 2022-04-18
auduongxuan/CVE-2022-26809
★ 7 · 2022-04-14
Lay0us/CVE-2022-26809-RCE

This repository contains a PoC for remote code execution CVE-2022-26809

★ 0 · 2022-04-21
CVE-2024-1709
HOTMULTI PoC
PoCs 5 ★ 113 Last push 2024-09-12 (2 years ago)

Fetching description from NVD…

Show 5 repositories
W01fh4cker/ScreenConnect-AuthBypass-RCE

ScreenConnect AuthBypass(cve-2024-1709) --> RCE!!!

★ 113 · 2024-07-16
HussainFathy/CVE-2024-1709

A Scanner for CVE-2024-1709 - ConnectWise SecureConnect Authentication Bypass Vulnerability

★ 3 · 2024-02-26
AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-

Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)

★ 0 · 2024-09-12
PoCs 1 ★ 138 Last push 2024-09-07 (2 years, 1 month ago)

Fetching description from NVD…

Show 1 repositories
mellow-hype/cve-2024-20017

exploits for CVE-2024-20017

★ 138 · 2024-09-07
PoCs 3 ★ 178 Last push 2024-08-21 (2 years, 1 month ago)

Fetching description from NVD…

Show 3 repositories
alfarom256/CVE-2022-3699

Lenovo Diagnostics Driver EoP - Arbitrary R/W

★ 178 · 2022-12-05
estimated1337/lenovo_exec

CVE-2022-3699 with arbitrary kernel code execution capability

★ 73 · 2022-12-27
Eap2468/CVE-2022-3699

Proof of Concept exploit for CVE-2022-3699

★ 0 · 2024-08-21
< Prev Page 13 / 21 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.