Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
CVE-2025-41249
CVE-2024-36774
CVE-2022-21812
8 contacts in last 24h
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
504 results
PoCs 3
★ 450
Last push 2026-10-08 (1 day, 7 hours ago)
Fetching description from NVD…
Show 3 repositories
LSPosed/LSPromise
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
★ 450 · 2026-09-09
Supersonic/TLPE
CVE-2026-49881, using insecure context creation in Android 17's Telecom service to execute arbitrary code as UID 1000 system_server from an unprivileged app
★ 104 · 2026-09-09
PoCs 15
★ 278
Last push 2026-10-08 (1 day, 15 hours ago)
Fetching description from NVD…
Show 8 of 15 repositories
Qingizi7/cve-2025-21479_iqooneo8
Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell
★ 7 · 2026-09-06
RamenFast/zenfone9-root
Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.
★ 4 · 2026-09-18
PoCs 17
★ 114
Last push 2026-10-08 (1 day, 19 hours ago)
Fetching description from NVD…
Show 8 of 17 repositories
ynsmroztas/KeySniper
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
★ 114 · 2026-09-06
PoCs 23
★ 725
Last push 2026-10-08 (1 day, 20 hours ago)
Fetching description from NVD…
Show 8 of 23 repositories
bhdresh/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Of…
★ 725 · 2017-11-19
Exploit-install/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…
★ 7 · 2017-04-22
jacobsoo/RTF-Cleaner
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
★ 3 · 2017-12-08
n1shant-sinha/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…
★ 2 · 2017-04-23
PoCs 70
★ 208
Last push 2026-10-08 (1 day, 23 hours ago)
Fetching description from NVD…
Show 8 of 70 repositories
PoCs 27
★ 203
Last push 2026-10-07 (2 days, 14 hours ago)
Fetching description from NVD…
Show 8 of 27 repositories
Zombie-Kaiser/cve-2024-4367-PoC-fixed
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…
★ 12 · 2024-06-13
snyk-labs/pdfjs-vuln-demo
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
★ 10 · 2026-10-07
clarkio/pdfjs-vuln-demo
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
★ 4 · 2024-11-10
PoCs 33
★ 137
Last push 2026-10-07 (2 days, 17 hours ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 1
★ 171
Last push 2026-10-07 (2 days, 18 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 124
★ 101
Last push 2026-10-07 (2 days, 20 hours ago)
Fetching description from NVD…
Show 8 of 124 repositories
AnonKryptiQuz/NextSploit
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
★ 92 · 2025-04-12
PoCs 75
★ 1837
Last push 2026-10-07 (2 days, 21 hours ago)
Fetching description from NVD…
Show 8 of 75 repositories
bb00/zer0dump
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
★ 179 · 2023-03-02
PoCs 62
★ 1015
Last push 2026-10-07 (2 days, 23 hours ago)
Fetching description from NVD…
Show 8 of 62 repositories
r1is/CVE-2022-0847
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…
★ 282 · 2023-02-02
hyln9/VIKIROOT
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
★ 271 · 2017-01-27
PoCs 11
★ 378
Last push 2026-10-07 (3 days, 3 hours ago)
Fetching description from NVD…
Show 8 of 11 repositories
PoCs 76
★ 508
Last push 2026-10-06 (3 days, 15 hours ago)
Fetching description from NVD…
Show 8 of 76 repositories
rfxn/cpanel-sessionscribe
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…
★ 13 · 2026-05-21
PoCs 42
★ 777
Last push 2026-10-06 (3 days, 15 hours ago)
Fetching description from NVD…
Show 8 of 42 repositories
duy-31/CVE-2024-21413
Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC
★ 156 · 2024-02-17
PoCs 84
★ 442
Last push 2026-10-06 (4 days, 1 hour ago)
Fetching description from NVD…
Show 8 of 84 repositories
PolarisLab/S2-045
Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html
★ 23 · 2017-03-07
PoCs 12
★ 1895
Last push 2026-10-05 (4 days, 12 hours ago)
Fetching description from NVD…
Show 8 of 12 repositories
pentestfunctions/BlueDucky
🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)
★ 1895 · 2026-02-11
Danyw24/blueXploit
Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)
★ 16 · 2026-07-23
Sergeb250/BlueDucky
BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…
★ 2 · 2025-08-26
xG3nesis/RustyInjector
Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).
★ 1 · 2025-01-25
hegaz0y/-BuL
EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…
★ 1 · 2026-05-31
PoCs 7
★ 559
Last push 2026-10-04 (5 days, 10 hours ago)
Fetching description from NVD…
Show 7 repositories
reswitched/rcm-modchips
Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)
★ 21 · 2018-05-22
nikameru/nxboot
Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")
★ 2 · 2026-10-04
Resi-le/NXLoader
An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability
★ 1 · 2025-12-21
oliviaholly/fusee-gelee
An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.
★ 0 · 2026-03-30
PoCs 6
★ 160
Last push 2026-10-03 (1 week ago)
Fetching description from NVD…
Show 6 repositories
PoCs 84
★ 3551
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 84 repositories
amlweems/xzbot
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
★ 3551 · 2024-04-03
PoCs 58
★ 195
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…
★ 195 · 2025-03-14
x00byte/PutScanner
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
★ 9 · 2025-07-19
PoCs 25
★ 339
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 25 repositories
peterpt/eternal_scanner
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
★ 339 · 2024-07-31
AtithKhawas/autoblue
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …
★ 5 · 2024-12-30
sethwhy/BlueDoor
Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…
★ 2 · 2024-12-22
PoCs 60
★ 783
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 60 repositories
ignis-sec/CVE-2023-38831-RaRCE
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
★ 113 · 2023-08-27
xaitax/WinRAR-CVE-2023-38831
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …
★ 17 · 2023-09-08
PoCs 9
★ 332
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 9 repositories
hakaioffsec/CVE-2024-21338
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
★ 332 · 2024-04-16
PoCs 11
★ 206
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 11 repositories
dinosn/fastjson-jsontype-rce-lab
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attack…
★ 206 · 2026-07-27
PoCs 24
★ 194
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 24 repositories
4xura/CVE-2025-30208
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
★ 12 · 2025-04-09
ThemeHackers/CVE-2025-30208
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
★ 10 · 2025-06-29
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.