Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
357PoC updated in 7 days
filters
504 results
PoCs 9
★ 145
Last push 2026-07-20 (2 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
Cracked5pider/eop24-26229
A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user
★ 41 · 2024-08-15
team-MineDEV/CVE-2024-26229
Windows CSC服务特权提升漏洞。 当程序向缓冲区写入的数据超出其处理能力时,就会发生基于堆的缓冲区溢出,从而导致多余的数据溢出到相邻的内存区域。这种溢出会损坏内存,并可能使攻击者能够执行任意代码或未经授权访问系统。本质上,攻击者可以编写触发溢出的恶意代码或输入,从而控制受影响的系统、执行任意命令、安装恶意软…
★ 11 · 2024-06-16
PoCs 6
★ 163
Last push 2026-07-16 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 4
★ 232
Last push 2026-07-16 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 4 repositories
MrAle98/CVE-2025-21333-POC
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
★ 232 · 2025-04-12
PoCs 13
★ 679
Last push 2026-07-15 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
PoCs 15
★ 238
Last push 2026-07-14 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
Plazmaz/CVE-2019-18634
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
★ 59 · 2020-02-19
PoCs 11
★ 719
Last push 2026-07-13 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 11 repositories
uziii2208/CVE-2025-33073
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
★ 67 · 2025-11-14
matejsmycka/CVE-2025-33073-checker
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samb…
★ 0 · 2025-07-31
PoCs 15
★ 190
Last push 2026-07-12 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
jaiguptanick/CVE-2019-0232
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
★ 33 · 2021-09-04
PoCs 4
★ 206
Last push 2026-07-12 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 4 repositories
Jnnshschl/CVE-2023-38146
PoC for the ThemeBleed Windows 11 CVE-2023-38146 written in python using impacket. https://jnns.de/posts/cve-2023-38146-poc/
★ 27 · 2024-05-01
PoCs 7
★ 186
Last push 2026-07-09 (3 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 26
★ 1484
Last push 2026-07-08 (3 months ago)
Fetching description from NVD…
Show 8 of 26 repositories
Schira4396/VcenterKiller
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密…
★ 1484 · 2024-04-25
tunelko/CVE-2022-22954-PoC
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
★ 16 · 2024-02-13
PoCs 6
★ 1069
Last push 2026-07-07 (3 months ago)
Fetching description from NVD…
Show 6 repositories
Ridter/noPac
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
★ 1022 · 2023-01-29
ly4k/Pachine
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
★ 278 · 2022-01-13
xLTJ/noPac
Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287
★ 0 · 2026-07-07
PoCs 29
★ 377
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 8 of 29 repositories
dsssssssm/WSOB
😭 WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
★ 26 · 2023-05-23
PoCs 4
★ 115
Last push 2026-07-04 (3 months ago)
Fetching description from NVD…
Show 4 repositories
PoCs 7
★ 199
Last push 2026-07-03 (3 months ago)
Fetching description from NVD…
Show 7 repositories
bp2008/DahuaLoginBypass
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
★ 199 · 2026-07-03
PoCs 55
★ 374
Last push 2026-07-01 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 of 55 repositories
PoCs 86
★ 1359
Last push 2026-06-26 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 of 86 repositories
PoCs 8
★ 323
Last push 2026-06-24 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 repositories
d3ndr1t30x/CVE-2022-37706
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script h…
★ 1 · 2024-12-10
PoCs 10
★ 126
Last push 2026-06-21 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Mr-xn/CVE-2024-36991
Path Traversal On The "/Modules/Messaging/" Endpoint In Splunk Enterprise On Windows
★ 9 · 2024-07-06
gunzf0x/CVE-2024-36991
Proof of Concept for CVE-2024-36991. Path traversal for Splunk versions below 9.2.2, 9.1.5, and 9.0.10 for Windows which allows arbitrary file read.
★ 4 · 2025-03-31
0xFZin/CVE-2024-36991
Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed.
★ 3 · 2026-06-21
th3gokul/CVE-2024-36991
CVE-2024-36991: Path traversal that affects Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10.
★ 2 · 2024-07-06
TheStingR/CVE-2024-36991-Tool
This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive files and…
★ 2 · 2025-10-30
PoCs 33
★ 126
Last push 2026-06-19 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 19
★ 135
Last push 2026-06-16 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 10
★ 527
Last push 2026-06-16 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Admin9961/CVE-2024-30088
Questa repository contiene una replica (tentativo di replica) scritto in Python per CVE-2024-30088.
★ 2 · 2024-07-27
PoCs 6
★ 120
Last push 2026-06-12 (3 months, 4 weeks ago)
Fetching description from NVD…
Show 6 repositories
hacefresko/CVE-2021-4045
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
★ 120 · 2024-10-31
0xbinder/CVE-2021-4045
🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓
★ 9 · 2023-12-27
234329a423853/CVE-2021-4045
CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all firmware …
★ 1 · 2025-12-11
PoCs 14
★ 506
Last push 2026-06-11 (3 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 15
★ 140
Last push 2026-06-09 (4 months ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 15
★ 332
Last push 2026-06-06 (4 months ago)
Fetching description from NVD…
Show 8 of 15 repositories
0xbinder/CVE-2024-0044
CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13
★ 332 · 2024-12-02
canyie/CVE-2024-0044
RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation from adb to i…
★ 180 · 2024-09-30
sridhar-sec/EvilDroid
EvilDroid automates the exploitation of CVE-2024-0044, installing malicious payloads on a target device and extracting sensitive data. It features automated AD…
★ 31 · 2025-09-06
007CRIPTOGRAFIA/c-CVE-2024-0044
CVE-2024-0044: uma vulnerabilidade de alta gravidade do tipo "executar como qualquer aplicativo" que afeta as versões 12 e 13 do Android
★ 4 · 2024-07-11
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.