Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

504 results

CVE-2026-49881
FRESH PoCHOT
PoCs 3 ★ 450 Last push 2026-10-08 (1 day, 7 hours ago)

Fetching description from NVD…

Show 3 repositories
LSPosed/LSPromise

Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284

★ 450 · 2026-09-09
Supersonic/TLPE

CVE-2026-49881, using insecure context creation in Android 17's Telecom service to execute arbitrary code as UID 1000 system_server from an unprivileged app

★ 104 · 2026-09-09
Lewason/mhl-off-hook-writeup

a challenge for a CVE-2026-49881

★ 0 · 2026-10-08
CVE-2025-21479
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 278 Last push 2026-10-08 (1 day, 15 hours ago)

Fetching description from NVD…

Show 8 of 15 repositories
zhuowei/cheese

CVE-2025-21479 proof-of-concept, I think

★ 278 · 2025-08-16
sarabpal-dev/cheese-cake

A proof-of-concept for CVE-2025-21479, chained with a Dirty Pagetable technique.

★ 35 · 2025-12-31
ma4the/omae-wa-cheese-da

CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)

★ 17 · 2026-06-30
CamsShaft/SELinux-Permissive-Only-CVE-2025-21479

This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the adreno kgsl on many devices including Samsung snapd…

★ 8 · 2026-08-14
Qingizi7/cve-2025-21479_iqooneo8

Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

★ 7 · 2026-09-06
linux-tools/VIVO-IQOO-Neo9-Root-Tools

Support OriginOS 4~ OriginOS 6(Some firmware requires manual, individual adaptation), using CVE-2025-21479,CVE-2026-43499

★ 5 · 2026-10-08
RamenFast/zenfone9-root

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

★ 4 · 2026-09-18
CVE-2026-18963
FRESH PoCHOTMULTI PoC
PoCs 17 ★ 114 Last push 2026-10-08 (1 day, 19 hours ago)

Fetching description from NVD…

Show 8 of 17 repositories
ynsmroztas/KeySniper

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

★ 114 · 2026-09-06
Snizi/CVE-2026-18963-Exploit

Exploit for KeyCloak CVE-2026-18963

★ 46 · 2026-08-20
Red-Darkin/CVE-2026-18963-keycloak

CVE-2026-18963

★ 20 · 2026-08-25
EQSTLab/CVE-2026-18963

Keycloak reset-credentials flow bypass

★ 17 · 2026-09-28
kyos-public/keycloak-cve-2026-18963-hunt

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

★ 16 · 2026-08-24
prot0tw/Keycloak_CVE-2026-18963_PoC

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

★ 15 · 2026-08-26
T0w0T/POC-CVE-2026-18963
★ 4 · 2026-08-24
alt3kx/CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

★ 4 · 2026-08-28
CVE-2017-0199
FRESH PoCHOTMULTI PoC
PoCs 23 ★ 725 Last push 2026-10-08 (1 day, 20 hours ago)

Fetching description from NVD…

Show 8 of 23 repositories
bhdresh/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Of…

★ 725 · 2017-11-19
haibara3839/CVE-2017-0199-master

CVE-2017-0199

★ 16 · 2017-04-19
NotAwful/CVE-2017-0199-Fix

Quick and dirty fix to OLE2 executing code via .hta

★ 13 · 2017-04-24
SyFi/cve-2017-0199
★ 12 · 2017-04-13
Exploit-install/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…

★ 7 · 2017-04-22
jacobsoo/RTF-Cleaner

RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759

★ 3 · 2017-12-08
mzakyz666/PoC-CVE-2017-0199

Exploit toolkit for vulnerability RCE Microsoft RTF

★ 2 · 2017-04-22
n1shant-sinha/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…

★ 2 · 2017-04-23
CVE-2026-24061
FRESH PoCHOTMULTI PoC
PoCs 70 ★ 208 Last push 2026-10-08 (1 day, 23 hours ago)

Fetching description from NVD…

Show 8 of 70 repositories
SafeBreach-Labs/CVE-2026-24061

Exploitation of CVE-2026-24061

★ 208 · 2026-01-22
JayGLXR/CVE-2026-24061-POC
★ 68 · 2026-01-22
ZeroDayEvil/CVE-2026-24061
★ 22 · 2026-09-28
parameciumzhang/Tell-Me-Root

基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具

★ 21 · 2026-01-23
Lingzesec/CVE-2026-24061-GUI

CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具

★ 17 · 2026-01-28
leonjza/inetutils-telnetd-auth-bypass

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

★ 12 · 2026-01-22
Chocapikk/CVE-2026-24061
★ 12 · 2026-01-22
ekomsSavior/telnet_scan

scanner/exploiter CVE-2026-24061 & CVE-2026-32746

★ 12 · 2026-05-22
CVE-2024-4367
FRESH PoCHOTMULTI PoC
PoCs 27 ★ 203 Last push 2026-10-07 (2 days, 14 hours ago)

Fetching description from NVD…

Show 8 of 27 repositories
LOURC0D3/CVE-2024-4367-PoC

CVE-2024-4367 & CVE-2024-34342 Proof of Concept

★ 203 · 2024-06-07
s4vvysec/CVE-2024-4367-POC

CVE-2024-4367 arbitrary js execution in pdf js

★ 57 · 2024-05-20
Zombie-Kaiser/cve-2024-4367-PoC-fixed

PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…

★ 12 · 2024-06-13
spaceraccoon/detect-cve-2024-4367

YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js

★ 11 · 2024-05-27
snyk-labs/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 10 · 2026-10-07
UnHackerEnCapital/PDFernetRemotelo

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

★ 6 · 2024-06-20
Masamuneee/CVE-2024-4367-Analysis

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

★ 5 · 2024-09-04
clarkio/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 4 · 2024-11-10
CVE-2019-2215
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 137 Last push 2026-10-07 (2 days, 17 hours ago)

Fetching description from NVD…

Show 8 of 33 repositories
kangtastic/cve-2019-2215

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

★ 137 · 2019-10-15
timwr/CVE-2019-2215
★ 79 · 2019-11-12
sharif-dev/AndroidKernelVulnerability

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

★ 73 · 2022-09-04
0xbinder/android-kernel-exploitation-lab

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

★ 44 · 2025-04-24
DimitriFourny/cve-2019-2215

Android privilege escalation via an use-after-free in binder.c

★ 41 · 2020-04-14
LIznzn/CVE-2019-2215

Temproot for Bravia TV via CVE-2019-2215.

★ 26 · 2020-02-20
stevejubx/CVE-2019-2215

Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC

★ 17 · 2023-12-21
c3r34lk1ll3r/CVE-2019-2215

PoC for old Binder vulnerability (based on P0 exploit)

★ 14 · 2020-10-27
CVE-2025-26125
FRESH PoCHOT
PoCs 1 ★ 171 Last push 2026-10-07 (2 days, 18 hours ago)

Fetching description from NVD…

Show 1 repositories
ZeroMemoryEx/CVE-2025-26125

( 0day ) Local Privilege Escalation in IObit Malware Fighter

★ 171 · 2026-10-07
CVE-2025-29927
FRESH PoCHOTMULTI PoC
PoCs 124 ★ 101 Last push 2026-10-07 (2 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 124 repositories
aydinnyunus/CVE-2025-29927

CVE-2025-29927 Proof of Concept

★ 101 · 2025-03-23
AnonKryptiQuz/NextSploit

NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js

★ 92 · 2025-04-12
websecnl/CVE-2025-29927-PoC-Exploit

Proof-of-Concept for Authorization Bypass in Next.js Middleware

★ 20 · 2025-03-23
6mile/nextjs-CVE-2025-29927

A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability

★ 19 · 2025-03-23
azu/nextjs-cve-2025-29927-poc

Next.js PoC for CVE-2025-29927

★ 15 · 2025-03-24
UNICORDev/exploit-CVE-2025-29927

Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass

★ 14 · 2025-04-15
MuhammadWaseem29/CVE-2025-29927-POC

Authorization Bypass in Next.js Middleware

★ 11 · 2025-03-23
CVE-2020-1472
FRESH PoCHOTMULTI PoC
PoCs 75 ★ 1837 Last push 2026-10-07 (2 days, 21 hours ago)

Fetching description from NVD…

Show 8 of 75 repositories
bvcyber/CVE-2020-1472

Test tool for CVE-2020-1472

★ 1837 · 2025-06-27
dirkjanm/CVE-2020-1472

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

★ 1329 · 2020-11-03
risksense/zerologon

Exploit for zerologon cve-2020-1472

★ 708 · 2020-10-15
VoidSec/CVE-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

★ 399 · 2020-11-05
bb00/zer0dump

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

★ 179 · 2023-03-02
mstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

★ 113 · 2020-09-16
Rvn0xsy/ZeroLogon

CVE-2020-1472 C++

★ 83 · 2022-09-02
zeronetworks/zerologon

Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB

★ 61 · 2023-05-01
CVE-2016-5195
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 1015 Last push 2026-10-07 (2 days, 23 hours ago)

Fetching description from NVD…

Show 8 of 62 repositories
timwr/CVE-2016-5195

CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

★ 1015 · 2021-02-03
firefart/dirtycow

Dirty Cow exploit - CVE-2016-5195

★ 932 · 2025-07-30
scumjr/dirtycow-vdso

PoC for Dirty COW (CVE-2016-5195)

★ 512 · 2022-03-16
gbonacini/CVE-2016-5195

A CVE-2016-5195 exploit example.

★ 341 · 2017-03-21
r1is/CVE-2022-0847

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…

★ 282 · 2023-02-02
hyln9/VIKIROOT

CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow

★ 271 · 2017-01-27
Brucetg/DirtyCow-EXP

编译好的脏牛漏洞(CVE-2016-5195)EXP

★ 141 · 2018-05-27
DavidBuchanan314/cowroot

Universal Android root tool based on CVE-2016-5195. Watch this space.

★ 32 · 2016-10-29
CVE-2022-0185
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 378 Last push 2026-10-07 (3 days, 3 hours ago)

Fetching description from NVD…

Show 8 of 11 repositories
Crusaders-of-Rust/CVE-2022-0185

CVE-2022-0185

★ 378 · 2022-04-25
chenaotian/CVE-2022-0185

CVE-2022-0185 POC and Docker and Analysis write up

★ 37 · 2022-05-24
veritas501/CVE-2022-0185-PipeVersion

CVE-2022-0185 exploit rewritten with pipe primitive

★ 16 · 2022-04-05
featherL/CVE-2022-0185-exploit

CVE-2022-0185 exploit

★ 3 · 2022-11-02
dcheng69/CVE-2022-0185-Case-Study
★ 3 · 2024-05-09
khaclep007/CVE-2022-0185
★ 0 · 2022-01-27
sandesh9978/CVE-2022-0185-Analysis-and-Exploit

Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.

★ 0 · 2026-03-20
CVE-2026-41940
FRESH PoCHOTMULTI PoC
PoCs 76 ★ 508 Last push 2026-10-06 (3 days, 15 hours ago)

Fetching description from NVD…

Show 8 of 76 repositories
ynsmroztas/cPanelSniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

★ 508 · 2026-05-01
assetnote/cpanel2shell-scanner

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

★ 92 · 2026-05-18
XsanFlip/poc-cpanel-cve-2026-41940
★ 64 · 2026-05-01
adriyansyah-mf/cve-2026-41940-poc
★ 28 · 2026-04-30
ZeroDayEvil/CVE-2026-41940-PoC
★ 28 · 2026-09-28
Sachinart/CVE-2026-41940-cpanel-0day

CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani

★ 25 · 2026-04-29
ilmndwntr/CVE-2026-41940-MASS-EXPLOIT

CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT

★ 13 · 2026-04-30
rfxn/cpanel-sessionscribe

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…

★ 13 · 2026-05-21
CVE-2024-21413
FRESH PoCHOTMULTI PoC
PoCs 42 ★ 777 Last push 2026-10-06 (3 days, 15 hours ago)

Fetching description from NVD…

Show 8 of 42 repositories
xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

★ 777 · 2024-02-19
CMNatic/CVE-2024-21413

CVE-2024-21413 PoC for THM Lab

★ 289 · 2024-03-13
duy-31/CVE-2024-21413

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

★ 156 · 2024-02-17
ThemeHackers/CVE-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

★ 25 · 2025-06-05
r00tb1t/CVE-2024-21413-POC

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

★ 17 · 2024-02-16
mmathivanan17/CVE-2024-21413

Outlook exploitation

★ 11 · 2025-11-30
ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. Monik…

★ 4 · 2024-02-24
CVE-2017-5638
FRESH PoCHOTMULTI PoC
PoCs 84 ★ 442 Last push 2026-10-06 (4 days, 1 hour ago)

Fetching description from NVD…

Show 8 of 84 repositories
mazen160/struts-pwn

An exploit for Apache Struts CVE-2017-5638

★ 442 · 2018-05-21
Flyteas/Struts2-045-Exp

Struts2 S2-045(CVE-2017-5638)Exp with GUI

★ 61 · 2017-03-13
immunio/apache-struts2-CVE-2017-5638

Demo Application and Exploit

★ 34 · 2017-03-13
jas502n/S2-045-EXP-POC-TOOLS

S2-045 漏洞 POC-TOOLS CVE-2017-5638

★ 25 · 2021-08-18
PolarisLab/S2-045

Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html

★ 23 · 2017-03-07
xsscx/cve-2017-5638

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit

★ 22 · 2017-03-12
jas502n/st2-046-poc

st2-046-poc CVE-2017-5638

★ 21 · 2018-08-17
ret2jazzy/Struts-Apache-ExploitPack

These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)

★ 16 · 2017-03-12
CVE-2023-45866
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 1895 Last push 2026-10-05 (4 days, 12 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
pentestfunctions/BlueDucky

🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)

★ 1895 · 2026-02-11
Danyw24/blueXploit

Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)

★ 16 · 2026-07-23
Eason-zz/BluetoothDucky

CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)

★ 15 · 2024-01-15
AvishekDhakal/CVE-2023-45866_EXPLOITS

Exploits Tested in Mi A2 Lite and Realme 2 pro

★ 3 · 2024-09-02
Sergeb250/BlueDucky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…

★ 2 · 2025-08-26
xG3nesis/RustyInjector

Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).

★ 1 · 2025-01-25
hegaz0y/-BuL

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…

★ 1 · 2026-05-31
jjjjjjjj987/cve-2023-45866-py
★ 0 · 2024-01-23
CVE-2018-6242
FRESH PoCHOTMULTI PoC
PoCs 7 ★ 559 Last push 2026-10-04 (5 days, 10 hours ago)

Fetching description from NVD…

Show 7 repositories
DavidBuchanan314/NXLoader

My first Android app: Launch Fusée Gelée payloads from stock Android (CVE-2018-6242)

★ 559 · 2022-12-11
reswitched/rcm-modchips

Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)

★ 21 · 2018-05-22
austinhartzheim/fusee-gelee

Rust implementation of the Fusée Gelée exploit (CVE-2018-6242) for Tegra processors.

★ 5 · 2022-12-21
nikameru/nxboot

Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")

★ 2 · 2026-10-04
Resi-le/NXLoader

An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability

★ 1 · 2025-12-21
Swiftloke/fusee-toy

Implementation of CVE-2018-6242 (AKA Fusée Gelée, AKA shofel2)

★ 0 · 2022-05-25
oliviaholly/fusee-gelee

An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.

★ 0 · 2026-03-30
CVE-2021-21315
HOTMULTI PoC
PoCs 6 ★ 160 Last push 2026-10-03 (1 week ago)

Fetching description from NVD…

Show 6 repositories
ForbiddenProgrammer/CVE-2021-21315-PoC

CVE 2021-21315 PoC

★ 160 · 2021-06-09
alikarimi999/CVE-2021-21315
★ 4 · 2021-09-20
G01d3nW01f/CVE-2021-21315

rust noob tried write easy exploit code with rust lang

★ 1 · 2021-12-27
MazX0p/CVE-2021-21315-exploit

systeminformation

★ 0 · 2021-07-18
xMohamed0/CVE-2021-21315-POC
★ 0 · 2021-11-14
jimahub/scenario-d-kev

Thesis scenario test (research only): Scenario D: KEV override path - [email protected] CVE-2021-21315

★ 0 · 2026-10-03
CVE-2024-3094
HOTMULTI PoC
PoCs 84 ★ 3551 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 84 repositories
amlweems/xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

★ 3551 · 2024-04-03
lockness-Ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

★ 146 · 2024-04-02
FabioBaroni/CVE-2024-3094-checker

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

★ 72 · 2024-03-31
robertdfrench/ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

★ 60 · 2026-09-25
byinarie/CVE-2024-3094-info

Information for CVE-2024-3094

★ 54 · 2024-04-01
jfrog/cve-2024-3094-tools
★ 44 · 2024-04-07
gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be v…

★ 26 · 2024-04-07
0xlane/xz-cve-2024-3094

XZ Backdoor Extract(Test on Ubuntu 23.10)

★ 17 · 2024-04-02
CVE-2025-24813
HOTMULTI PoC
PoCs 58 ★ 195 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813

his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…

★ 195 · 2025-03-14
iSee857/CVE-2025-24813-PoC

Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)

★ 98 · 2025-04-02
drcrypterdotru/Apache-GOExploiter

Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast

★ 20 · 2025-10-05
mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-

Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)

★ 19 · 2025-05-25
charis3306/CVE-2025-24813

CVE-2025-24813利用工具

★ 16 · 2025-03-16
qzy0x/cve-2025-24813_poc

cve-2025-24813验证脚本

★ 11 · 2025-03-14
Franconyu/Poc_for_CVE-2025-24813

CVE-2025-24813 poc

★ 9 · 2025-04-11
x00byte/PutScanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

★ 9 · 2025-07-19
CVE-2017-0144
HOTMULTI PoC
PoCs 25 ★ 339 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 25 repositories
peterpt/eternal_scanner

An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)

★ 339 · 2024-07-31
AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint

This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a…

★ 15 · 2025-07-10
AtithKhawas/autoblue

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …

★ 5 · 2024-12-30
sethwhy/BlueDoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…

★ 2 · 2024-12-22
0xBlackash/CVE-2017-0144

CVE-2017-0144

★ 2 · 2026-06-14
kimocoder/eternalblue

CVE-2017-0144

★ 1 · 2024-04-01
MedX267/EternalBlue-Vulnerability-Scanner

This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.

★ 1 · 2025-02-03
CVE-2023-38831
HOTMULTI PoC
PoCs 60 ★ 783 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 60 repositories
b1tg/CVE-2023-38831-winrar-exploit

CVE-2023-38831 winrar exploit generator

★ 783 · 2023-11-26
Garck3h/cve-2023-38831

一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。

★ 126 · 2023-08-27
ignis-sec/CVE-2023-38831-RaRCE

An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23

★ 113 · 2023-08-27
BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

★ 91 · 2023-08-24
HDCE-inc/CVE-2023-38831

CVE-2023-38831 PoC (Proof Of Concept)

★ 89 · 2024-08-04
knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831

Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)

★ 40 · 2023-08-28
Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE

Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.

★ 22 · 2023-08-31
xaitax/WinRAR-CVE-2023-38831

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …

★ 17 · 2023-09-08
CVE-2024-21338
HOTMULTI PoC
PoCs 9 ★ 332 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 9 repositories
hakaioffsec/CVE-2024-21338

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 332 · 2024-04-16
Crowdfense/CVE-2024-21338

Windows AppLocker Driver (appid.sys) LPE

★ 81 · 2024-07-29
tykawaii98/CVE-2024-21338_PoC
★ 40 · 2024-06-23
Zombie-Kaiser/CVE-2024-21338-x64-build-

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 7 · 2024-05-22
MistyFir/CVE-2024-21338-Exploit
★ 7 · 2026-04-06
UMU618/CVE-2024-21338

Fork of https://github.com/hakaioffsec/CVE-2024-21338

★ 2 · 2024-04-17
wusijie/CVE-2024-21338-1

PoC for the Untrusted Pointer Dereference in the appid.sys driver

★ 2 · 2024-05-05
hackyboiz/kcfg-bypass

kcfg bypass example - CVE-2024-21338

★ 2 · 2025-01-12
CVE-2026-16723
HOTMULTI PoC
PoCs 11 ★ 206 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
dinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attack…

★ 206 · 2026-07-27
why-success/fastjson-rce-lab

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

★ 4 · 2026-07-28
1xPwn/CVE-2026-16723

A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.

★ 2 · 2026-09-30
HORKimhab/CVE-2026-16723

CVE-2026-16723

★ 1 · 2026-07-26
EQSTLab/CVE-2026-16723

Fastjson RCE

★ 1 · 2026-07-30
fazilbaig1/CVE-2026-16723

This is N-day patch we releasing by testing our model capabilities

★ 1 · 2026-07-31
Superman-L/CVE-2026-16723

fastjson jsontype利用

★ 1 · 2026-08-19
CVE-2025-30208
HOTMULTI PoC
PoCs 24 ★ 194 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
ThumpBo/CVE-2025-30208-EXP

CVE-2025-30208-EXP

★ 194 · 2025-04-01
xuemian168/CVE-2025-30208

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

★ 49 · 2025-04-13
4xura/CVE-2025-30208

A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).

★ 12 · 2025-04-09
marino-admin/Vite-CVE-2025-30208-Scanner

CVE-2025-30208-EXP 任意文件读取

★ 10 · 2025-03-27
ThemeHackers/CVE-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

★ 10 · 2025-06-29
jackieya/ViteVulScan

针对CVE-2025-30208和CVE-2025-31125的漏洞利用

★ 7 · 2025-04-10
4m3rr0r/CVE-2025-30208-PoC

CVE-2025-30208 - Vite Arbitrary File Read PoC

★ 7 · 2025-09-08
< Prev Page 3 / 21 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.