Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
354PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

504 results

CVE-2017-7494
FRESH PoCHOTMULTI PoC
PoCs 22 ★ 380 Last push 2026-10-09 (21 hours, 34 minutes ago)

Fetching description from NVD…

Show 8 of 22 repositories
opsxcq/exploit-CVE-2017-7494

SambaCry exploit and vulnerable container (CVE-2017-7494)

★ 380 · 2022-12-27
joxeankoret/CVE-2017-7494

Remote root exploit for the SAMBA CVE-2017-7494 vulnerability

★ 259 · 2021-03-09
betab0t/cve-2017-7494

Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)

★ 181 · 2017-07-26
Waffles-2/SambaCry

CVE-2017-7494 - Detection Scripts

★ 63 · 2017-05-26
brianwrf/SambaHunter

It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).

★ 58 · 2021-10-31
d3fudd/CVE-2017-7494_SambaCry

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

★ 7 · 2022-11-01
0xm4ud/noSAMBAnoCRY-CVE-2017-7494

CVE-2017-7494 python exploit

★ 5 · 2021-08-27
I-Rinka/BIT-EternalBlue-for-macOS_Linux

Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.

★ 4 · 2021-05-18
CVE-2020-11651
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 121 Last push 2026-10-09 (21 hours, 35 minutes ago)

Fetching description from NVD…

Show 8 of 15 repositories
jasperla/CVE-2020-11651-poc

PoC exploit of CVE-2020-11651 and CVE-2020-11652

★ 121 · 2020-07-10
rossengeorgiev/salt-security-backports

Salt security backports for CVE-2020-11651 & CVE-2020-11652

★ 108 · 2020-05-18
dozernz/cve-2020-11651
★ 106 · 2020-05-04
0xc0d/CVE-2020-11651

CVE-2020-11651: Proof of Concept

★ 40 · 2021-07-07
ssrsec/CVE-2020-11651-CVE-2020-11652-EXP

CVE-2020-11651&&CVE-2020-11652 EXP

★ 24 · 2023-03-21
chef-cft/salt-vulnerabilities

Checks for CVE-2020-11651 and CVE-2020-11652

★ 6 · 2021-08-24
kevthehermit/CVE-2020-11651

PoC for CVE-2020-11651

★ 6 · 2020-05-04
bravery9/SaltStack-Exp

CVE-2020-11651&&CVE-2020-11652 EXP

★ 5 · 2020-05-04
CVE-2019-5418
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 201 Last push 2026-10-09 (21 hours, 35 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
mpgn/CVE-2019-5418

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

★ 201 · 2021-04-05
mpgn/Rails-doubletap-RCE

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

★ 132 · 2023-01-19
brompwnie/CVE-2019-5418-Scanner

A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418

★ 36 · 2019-03-21
omarkurt/CVE-2019-5418

File Content Disclosure on Rails Test Case - CVE-2019-5418

★ 5 · 2019-03-18
random-robbie/CVE-2019-5418
★ 5 · 2019-11-19
Bad3r/RailroadBandit

a demo for Ruby on Rails CVE-2019-5418

★ 3 · 2019-04-11
kailing0220/CVE-2019-5418

Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再…

★ 2 · 2022-10-17
ztgrace/CVE-2019-5418-Rails3

Rails 3 PoC of CVE-2019-5418

★ 0 · 2023-07-13
CVE-2019-11043
FRESH PoCHOTMULTI PoC
PoCs 28 ★ 1833 Last push 2026-10-09 (21 hours, 35 minutes ago)

Fetching description from NVD…

Show 8 of 28 repositories
neex/phuip-fpizdam

Exploit for CVE-2019-11043

★ 1833 · 2019-11-12
theMiddleBlue/CVE-2019-11043

(PoC) Python version of CVE-2019-11043 exploit by neex

★ 147 · 2019-10-29
jas502n/CVE-2019-11043

php-fpm+Nginx RCE

★ 105 · 2020-08-20
akamajoris/CVE-2019-11043-Docker
★ 27 · 2019-10-28
k8gege/CVE-2019-11043

Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)

★ 16 · 2019-11-11
0th3rs-Security-Team/CVE-2019-11043

CVE-2019-11043 PHP7.x RCE

★ 14 · 2019-11-06
kriskhub/CVE-2019-11043

This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.

★ 14 · 2020-05-25
ypereirareis/docker-CVE-2019-11043

Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.

★ 8 · 2019-10-30
CVE-2014-0160
FRESH PoCHOTMULTI PoC
PoCs 73 ★ 2373 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 8 of 73 repositories
FiloSottile/Heartbleed

A checker (site and tool) for CVE-2014-0160

★ 2373 · 2021-02-24
musalbas/heartbleed-masstest

Multi-threaded tool for scanning many hosts for CVE-2014-0160.

★ 571 · 2015-07-02
titanous/heartbleeder

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

★ 452 · 2014-05-27
Lekensteyn/pacemaker

Heartbleed (CVE-2014-0160) client exploit

★ 331 · 2016-01-22
sensepost/heartbleed-poc

Test for SSL heartbeat vulnerability (CVE-2014-0160)

★ 171 · 2014-07-10
einaros/heartbleed-tools

OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.

★ 98 · 2014-06-18
mpgn/heartbleed-PoC

:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:

★ 85 · 2021-02-20
isgroup/openmagic

OpenSSL TLS heartbeat read overrun (CVE-2014-0160)

★ 40 · 2014-04-11
CVE-2018-15473
FRESH PoCHOTMULTI PoC
PoCs 42 ★ 533 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 8 of 42 repositories
Rhynorater/CVE-2018-15473-Exploit

Exploit written in Python for CVE-2018-15473 with threading and export formats

★ 533 · 2024-07-12
trimstray/massh-enum

OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).

★ 160 · 2019-11-15
epi052/cve-2018-15473

Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473

★ 117 · 2024-04-29
Sait-Nuri/CVE-2018-15473

OpenSSH 2.3 < 7.7 - Username Enumeration

★ 42 · 2023-09-04
r3dxpl0it/CVE-2018-15473

OpenSSH 7.7 - Username Enumeration

★ 17 · 2020-10-23
sergiovks/SSH-User-Enum-Python3-CVE-2018-15473

SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of …

★ 4 · 2023-03-12
gbonacini/opensshenum

CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug

★ 3 · 2018-10-17
MrDottt/CVE-2018-15473

CVE-2018-15473 Exploit

★ 3 · 2021-09-14
CVE-2023-32315
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 142 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
miko550/CVE-2023-32315

Openfire Console Authentication Bypass Vulnerability with RCE plugin

★ 61 · 2024-03-07
Ap0dexMe0/CVE-2023-32315

Perform With Massive Openfire Unauthenticated Users

★ 7 · 2023-07-24
izzz0/CVE-2023-32315-POC

CVE-2023-32315-Openfire-Bypass

★ 5 · 2023-07-11
gibran-abdillah/CVE-2023-32315

Tool for CVE-2023-32315 exploitation

★ 3 · 2023-08-31
ohnonoyesyes/CVE-2023-32315
★ 0 · 2023-06-14
CN016/Openfire-RCE-CVE-2023-32315-

Openfire未授权到RCE(CVE-2023-32315)复现

★ 0 · 2023-10-10
CVE-2019-10758
FRESH PoCHOT
PoCs 3 ★ 112 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 3 repositories
masahiro331/CVE-2019-10758
★ 112 · 2019-12-26
lp008/CVE-2019-10758

CVE-2019-10758

★ 5 · 2020-01-05
CyberCTF/vulhub-mongo-express-cve-2019-10758

Vulhub mongo-express/CVE-2019-10758: mongo-express Remote Code Execution (CVE-2019-10758), run with Isoloom

★ 0 · 2026-10-09
CVE-2018-10933
FRESH PoCHOTMULTI PoC
PoCs 38 ★ 496 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 8 of 38 repositories
blacknbunny/CVE-2018-10933

Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)

★ 496 · 2023-12-19
jobroche/libssh-scanner

Script to identify hosts vulnerable to CVE-2018-10933

★ 235 · 2018-11-04
SoledaD208/CVE-2018-10933

CVE-2018-10933 very simple POC

★ 126 · 2018-10-23
hackerhouse-opensource/cve-2018-10933

cve-2018-10933 libssh authentication bypass

★ 110 · 2026-02-02
jas502n/CVE-2018-10933

libssh CVE-2018-10933

★ 22 · 2018-10-20
kn6869610/CVE-2018-10933

Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred without a pr…

★ 14 · 2018-10-17
Virgula0/POC-CVE-2018-10933

LibSSH Authentication Bypass Exploit using RCE

★ 11 · 2018-10-25
marco-lancini/hunt-for-cve-2018-10933

Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)

★ 10 · 2018-10-18
CVE-2019-7609
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 165 Last push 2026-10-09 (21 hours, 36 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
LandGrey/CVE-2019-7609

exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts

★ 165 · 2023-08-29
jas502n/kibana-RCE

kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609

★ 89 · 2019-10-22
mpgn/CVE-2019-7609

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

★ 56 · 2019-12-20
hekadan/CVE-2019-7609
★ 20 · 2019-12-01
Cr4ckC4t/cve-2019-7609

Kibana <6.6.0 RCE written in python3

★ 4 · 2022-03-17
rhbb/CVE-2019-7609
★ 1 · 2020-04-03
dnr6419/CVE-2019-7609

Kibana Prototype Pollution

★ 1 · 2021-08-25
Akshay15-png/CVE-2019-7609

Exploit for CVE-2019-7609 in python

★ 1 · 2024-07-30
CVE-2024-23897
FRESH PoCHOTMULTI PoC
PoCs 48 ★ 209 Last push 2026-10-09 (21 hours, 37 minutes ago)

Fetching description from NVD…

Show 8 of 48 repositories
h4x0r-dz/CVE-2024-23897

CVE-2024-23897

★ 209 · 2024-01-28
binganao/CVE-2024-23897
★ 101 · 2024-02-01
wjlin0/CVE-2024-23897

CVE-2024-23897 - Jenkins 任意文件读取 利用工具

★ 86 · 2024-03-16
xaitax/CVE-2024-23897

CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.

★ 81 · 2024-02-29
godylockz/CVE-2024-23897

Proof of concept for CVE-2024-23897: Jenkins arbitrary file read

★ 46 · 2026-09-24
kaanatmacaa/CVE-2024-23897

Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)

★ 23 · 2024-02-05
Vozec/CVE-2024-23897

This repository presents a proof-of-concept of CVE-2024-23897

★ 18 · 2024-04-16
P4x1s/CVE-2024-23897

CVE-2024-23897 jenkins-cli

★ 15 · 2024-01-27
CVE-2017-12149
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 208 Last push 2026-10-09 (21 hours, 37 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
yunxu1/jboss-_CVE-2017-12149

CVE-2017-12149 jboss反序列化 可回显

★ 208 · 2019-03-13
sevck/CVE-2017-12149

CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)

★ 22 · 2017-11-22
1337g/CVE-2017-12149

CVE-2017-12149 JBOSS RCE (TESTED)

★ 15 · 2017-12-23
jreppiks/CVE-2017-12149

Jboss Java Deserialization RCE (CVE-2017-12149)

★ 14 · 2019-08-22
Xcatolin/jboss-deserialization

JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.

★ 0 · 2021-08-04
VVeakee/CVE-2017-12149
★ 0 · 2022-04-16
MrE-Fog/jboss-_CVE-2017-12149
★ 0 · 2023-08-06
JesseClarkND/CVE-2017-12149

Update of https://github.com/1337g/CVE-2017-12149 to work with python3

★ 0 · 2024-04-30
CVE-2022-44268
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 275 Last push 2026-10-09 (21 hours, 37 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator

★ 275 · 2023-02-02
voidz0r/CVE-2022-44268

A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read

★ 219 · 2025-03-24
Sybil-Scan/imagemagick-lfi-poc

ImageMagick LFI PoC [CVE-2022-44268]

★ 53 · 2023-11-06
kljunowsky/CVE-2022-44268

CVE-2022-44268 ImageMagick Arbitrary File Read - Proof of Concept exploit

★ 26 · 2023-12-29
entr0pie/CVE-2022-44268

PoC of Imagemagick's Arbitrary File Read

★ 13 · 2023-07-03
y1nglamore/CVE-2022-44268-ImageMagick-Vulnerable-Docker-Environment

The vulnerable recurrence docker environment for CVE-2022-44268

★ 10 · 2023-02-03
Vulnmachines/imagemagick-CVE-2022-44268

Imagemagick CVE-2022-44268

★ 8 · 2023-02-06
jnschaeffer/cve-2022-44268-detector

Detect images that likely exploit CVE-2022-44268

★ 5 · 2023-12-06
CVE-2025-55182
FRESH PoCHOTMULTI PoC
PoCs 463 ★ 2454 Last push 2026-10-09 (21 hours, 37 minutes ago)

Fetching description from NVD…

Show 8 of 463 repositories
assetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

★ 2454 · 2025-12-07
msanft/CVE-2025-55182

Explanation and full RCE PoC for CVE-2025-55182

★ 1431 · 2025-12-08
lachlan2k/React2Shell-CVE-2025-55182-original-poc

Original Proof-of-Concepts for React2Shell CVE-2025-55182

★ 1063 · 2025-12-05
ejpir/CVE-2025-55182-research

CVE-2025-55182 POC

★ 792 · 2025-12-08
mrknow001/RSC_Detector

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

★ 588 · 2025-12-05
emredavut/CVE-2025-55182

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478

★ 313 · 2025-12-06
ynsmroztas/NextRce

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

★ 266 · 2025-12-12
CVE-2021-41773
FRESH PoCHOTMULTI PoC
PoCs 172 ★ 212 Last push 2026-10-09 (21 hours, 37 minutes ago)

Fetching description from NVD…

Show 8 of 172 repositories
blasty/CVE-2021-41773

CVE-2021-41773 playground

★ 212 · 2021-10-07
inbug-team/CVE-2021-41773_CVE-2021-42013

CVE-2021-41773 CVE-2021-42013漏洞批量检测工具

★ 147 · 2021-10-09
thehackersbrain/CVE-2021-41773

Apache2 2.4.49 - LFI & RCE Exploit - CVE-2021-41773

★ 114 · 2022-03-12
HightechSec/scarce-apache2

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

★ 62 · 2021-10-07
MrCl0wnLab/SimplesApachePathTraversal

Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519

★ 61 · 2024-08-14
iilegacyyii/PoC-CVE-2021-41773
★ 52 · 2021-11-24
lorddemon/CVE-2021-41773-PoC
★ 39 · 2021-10-06
Vulnmachines/cve-2021-41773

CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.

★ 38 · 2022-08-30
CVE-2021-43798
FRESH PoCHOTMULTI PoC
PoCs 60 ★ 369 Last push 2026-10-09 (21 hours, 38 minutes ago)

Fetching description from NVD…

Show 8 of 60 repositories
jas502n/Grafana-CVE-2021-43798

Grafana Unauthorized arbitrary file reading vulnerability

★ 369 · 2023-02-14
A-D-Team/grafanaExp

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source …

★ 269 · 2025-10-17
pedrohavay/exploit-grafana-CVE-2021-43798

This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).

★ 46 · 2021-12-11
taythebot/CVE-2021-43798

CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)

★ 43 · 2021-12-07
zer0yu/CVE-2021-43798

Grafana Arbitrary File Reading Vulnerability

★ 27 · 2021-12-07
Mr-xn/CVE-2021-43798

CVE-2021-43798:Grafana 任意文件读取漏洞

★ 24 · 2021-12-07
MoCh3n/CVE-2021-43798-grafana_fileread

grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL

★ 17 · 2022-01-27
ScorpionsMAX/CVE-2021-43798-Grafana-POC

CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数

★ 14 · 2021-12-17
CVE-2021-22205
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 287 Last push 2026-10-09 (21 hours, 38 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Al1ex/CVE-2021-22205

CVE-2021-22205& GitLab CE/EE RCE

★ 287 · 2022-11-16
inspiringz/CVE-2021-22205

GitLab CE/EE Preauth RCE using ExifTool

★ 238 · 2022-01-16
mr-r3bot/Gitlab-CVE-2021-22205
★ 181 · 2021-11-02
XTeam-Wing/CVE-2021-22205

Pocsuite3 For CVE-2021-22205

★ 86 · 2021-10-28
r0eXpeR/CVE-2021-22205

CVE-2021-22205 Unauthorized RCE

★ 69 · 2021-10-28
whwlsfb/CVE-2021-22205

CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用

★ 23 · 2021-10-30
c0okB/CVE-2021-22205

CVE-2021-22205 RCE

★ 13 · 2022-07-04
keven1z/CVE-2021-22205

CVE-2021-22205 检测脚本,支持getshell和命令执行

★ 12 · 2022-07-25
CVE-2018-7600
FRESH PoCHOTMULTI PoC
PoCs 55 ★ 600 Last push 2026-10-09 (21 hours, 38 minutes ago)

Fetching description from NVD…

Show 8 of 55 repositories
dreadlocked/Drupalgeddon2

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

★ 600 · 2021-01-08
a2u/CVE-2018-7600

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

★ 353 · 2019-03-29
pimps/CVE-2018-7600

Exploit for Drupal 7 <= 7.57 CVE-2018-7600

★ 141 · 2018-04-26
g0rx/CVE-2018-7600-Drupal-RCE

CVE-2018-7600 Drupal RCE

★ 113 · 2018-04-18
firefart/CVE-2018-7600

CVE-2018-7600 - Drupal 7.x RCE

★ 71 · 2018-04-18
lorddemon/drupalgeddon2

Exploit for CVE-2018-7600.. called drupalgeddon2,

★ 11 · 2018-04-19
r3dxpl0it/CVE-2018-7600

CVE-2018-7600 POC (Drupal RCE)

★ 9 · 2020-08-31
zhzyker/CVE-2018-7600-Drupal-POC-EXP

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

★ 8 · 2020-04-07
CVE-2022-34265
FRESH PoCHOTMULTI PoC
PoCs 5 ★ 124 Last push 2026-10-09 (21 hours, 38 minutes ago)

Fetching description from NVD…

Show 5 repositories
aeyesec/CVE-2022-34265

PoC for CVE-2022-34265 (Django)

★ 124 · 2022-07-30
ZhaoQi99/CVE-2022-34265

PoC for CVE-2022-34265

★ 4 · 2022-08-26
traumatising/CVE-2022-34265

CVE-2022-34265 Vulnerability

★ 3 · 2022-07-13
CyberCTF/vulhub-django-cve-2022-34265

Vulhub django/CVE-2022-34265: Django Trunc and Extract SQL Injection (CVE-2022-34265), run with Isoloom

★ 0 · 2026-10-09
CVE-2014-6271
FRESH PoCHOTMULTI PoC
PoCs 95 ★ 232 Last push 2026-10-09 (21 hours, 39 minutes ago)

Fetching description from NVD…

Show 8 of 95 repositories
opsxcq/exploit-CVE-2014-6271

Shellshock exploit + vulnerable environment

★ 232 · 2023-05-11
scottjpack/shellshock_scanner

Python Scanner for "ShellShock" (CVE-2014-6271)

★ 46 · 2014-09-29
hmlio/vaas-cve-2014-6271

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

★ 22 · 2019-10-08
b4keSn4ke/CVE-2014-6271

Shellshock exploit aka CVE-2014-6271

★ 15 · 2022-04-01
cj1324/CGIShell

shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI

★ 13 · 2014-10-02
francisck/shellshock-cgi

A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server

★ 12 · 2015-06-19
indiandragon/Shellshock-Vulnerability-Scan

Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock

★ 11 · 2021-08-31
npm/ansible-bashpocalypse

Patch for CVE-2014-6271

★ 6 · 2014-09-24
CVE-2021-25646
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 1073 Last push 2026-10-09 (21 hours, 39 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
1n7erface/PocList

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…

★ 1073 · 2023-05-11
yaunsky/cve-2021-25646

Apache Druid 远程代码执行;检测脚本

★ 17 · 2021-02-03
j2ekim/CVE-2021-25646

Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646

★ 4 · 2021-12-12
k7pro/CVE-2021-25646-exp

CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具

★ 4 · 2025-02-18
givemefivw/CVE-2021-25646

CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本

★ 3 · 2021-04-15
lp008/CVE-2021-25646
★ 2 · 2021-02-03
Ormicron/CVE-2021-25646-GUI

CSharp CVE-2021-25646-GUI

★ 1 · 2021-02-05
CVE-2023-46604
FRESH PoCHOTMULTI PoC
PoCs 40 ★ 126 Last push 2026-10-09 (21 hours, 39 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ

Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)

★ 126 · 2024-01-20
Catherines77/ActiveMQ-EXPtools

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

★ 83 · 2026-06-27
Arlenhiack/ActiveMQ-RCE-Exploit

ActiveMQ RCE (CVE-2023-46604) 回显利用工具

★ 44 · 2024-09-13
evkl1d/CVE-2023-46604
★ 41 · 2023-11-06
trganda/ActiveMQ-RCE

CVE-2023-46604

★ 28 · 2023-10-26
duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell

This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserializa…

★ 19 · 2024-01-24
justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp

CVE-2023-46604 Apache ActiveMQ RCE exp 基于python

★ 5 · 2023-11-08
NKeshawarz/CVE-2023-46604-RCE
★ 4 · 2023-11-18
CVE-2021-1931
FRESH PoCHOT
PoCs 4 ★ 213 Last push 2026-10-09 (1 day, 2 hours ago)

Fetching description from NVD…

Show 4 repositories
starseed12345/QuestStack

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

★ 213 · 2026-08-28
FakeShell/CVE-2021-1931-BBRY-KEY2

proof of concept CVE-2021-1931 exploit for the blackberry key2 (le) that allows to flash unsigned images temporarily

★ 8 · 2025-05-04
aomsin2526/xperia_5_bl_unlocker_poc

My take on unlocking Xperia 5 SO-01M for p42 bootloader using CVE-2021-1931

★ 5 · 2026-10-09
stanw47/Blackberry-Key2-Research

BlackBerry KEY2 (BBF100-6) bootloader unlock (CVE-2021-1931), unlock-tool RE, recon, and LineageOS research

★ 1 · 2026-10-05
CVE-2022-26134
FRESH PoCHOTMULTI PoC
PoCs 72 ★ 1247 Last push 2026-10-09 (1 day, 3 hours ago)

Fetching description from NVD…

Show 8 of 72 repositories
W01fh4cker/Serein

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCMS v5.7.87…

★ 1247 · 2023-02-26
jbaines-r7/through_the_wire

CVE-2022-26134 Proof of Concept

★ 174 · 2022-06-06
hev0x/CVE-2022-26134

Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)

★ 44 · 2022-06-06
crowsec-edtech/CVE-2022-26134

CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection

★ 31 · 2022-06-03
nxtexploit/CVE-2022-26134

Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)

★ 29 · 2024-08-23
SNCKER/CVE-2022-26134

[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.

★ 26 · 2022-06-18
SIFalcon/confluencePot

Simple Honeypot for Atlassian Confluence (CVE-2022-26134)

★ 20 · 2022-06-07
CVE-2026-63030
FRESH PoCHOTMULTI PoC
PoCs 80 ★ 788 Last push 2026-10-08 (1 day, 6 hours ago)

Fetching description from NVD…

Show 8 of 80 repositories
Icex0/wp2shell-poc

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

★ 788 · 2026-08-11
manpisetsu/wp2shell

CVE-2026-63030 + CVE-2026-60137 exploit RCE chain

★ 178 · 2026-10-07
0xsha/wp2shell

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

★ 115 · 2026-07-18
ZephrFish/wp2shell-scanner

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

★ 66 · 2026-07-18
dinosn/wp2shell-lab

Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0…

★ 63 · 2026-07-22
NULL200OK/WP2Shell

WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, al…

★ 17 · 2026-07-18
securelayer7/WordPresShell

Pre-auth RCE PoC for CVE-2026-63030 / CVE-2026-60137 (WordPress core)

★ 17 · 2026-07-18
47Cid/wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

★ 15 · 2026-07-18
< Prev Page 2 / 21 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.