Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-64560
FRESH PoCMULTI PoC
PoCs 10 ★ 73 Last push 2026-10-09 (13 hours, 55 minutes ago)

Fetching description from NVD…

Show 8 of 10 repositories
quyicheng03-boop/xiaomi15-dada-cve-2026-64560

Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8

★ 21 · 2026-09-05
a23bc/op13-cve-2026-64560
★ 11 · 2026-09-27
qingle009/opace6-cve-2026-64560

OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

★ 7 · 2026-09-29
imkidz0/CVE-2026-64560-exploit

Exploit of CVE-2026-64560 for kernelCTF, LTS-6.12.95

★ 2 · 2026-10-03
Become-ILLUSORY/cve-2026-64560-a16

CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port

★ 1 · 2026-09-26
Wangs-official/opace6-cve-2026-64560

针对 OnePlus Ace6 设备的 cve-2026-64560 复现

★ 1 · 2026-09-25
CVE-2025-66478
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 430 Last push 2026-10-09 (14 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

★ 430 · 2025-12-16
vercel-labs/fix-react2shell-next

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

★ 401 · 2025-12-12
hackersatyamrastogi/react2shell-ultimate

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.

★ 157 · 2025-12-10
abtonc/next-cve-2025-66478
★ 11 · 2025-12-08
khadafigans/React2Shell

React2Shell - CVE-2025-66478 RCE Exploit

★ 6 · 2026-02-12
wangxso/CVE-2025-66478-POC

CVE-2025-66478 Proof of Concept

★ 5 · 2025-12-17
abdozkaya/rsc-security-auditor

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…

★ 5 · 2025-12-13
strainxx/react2shell-honeypot

My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)

★ 4 · 2025-12-08
CVE-2025-49844
FRESH PoCHOTMULTI PoC
PoCs 19 ★ 345 Last push 2026-10-09 (14 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 19 repositories
raminfp/redis_exploit

CVE-2025-49844 (RediShell)

★ 345 · 2025-10-07
dwisiswant0/CVE-2025-49844

CVE-2025-49844 – Redis Lua Parser Use-After-Free

★ 66 · 2025-10-07
saneki/cve-2025-49844

Proof-of-concept for CVE-2025-49844

★ 25 · 2025-11-20
lastvocher/redis-CVE-2025-49844
★ 14 · 2025-10-07
pedrorichil/CVE-2025-49844
★ 6 · 2025-10-08
Zain3311/CVE-2025-49844

🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.

★ 2 · 2026-10-09
MiclelsonCN/CVE-2025-49844_POC

CVE-2025-49844 POC

★ 2 · 2025-10-09
ksnnd32/redis_exploit

🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.

★ 1 · 2026-10-09
CVE-2025-32463
FRESH PoCHOTMULTI PoC
PoCs 69 ★ 529 Last push 2026-10-09 (14 hours, 27 minutes ago)

Fetching description from NVD…

Show 8 of 69 repositories
pr0v3rbs/CVE-2025-32463_chwoot

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

★ 529 · 2025-11-19
kh4sh3i/CVE-2025-32463

Local Privilege Escalation to Root via Sudo chroot in Linux

★ 476 · 2025-07-02
MohamedKarrab/CVE-2025-32463

Privilege escalation to root using sudo chroot, NO NEED for gcc installed.

★ 48 · 2025-10-06
K1tt3h/CVE-2025-32463-POC

CVE-2025-32463 Proof of concept

★ 30 · 2025-07-01
1xPwn/CVE-2025-32463

This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.

★ 26 · 2026-08-12
mirchr/CVE-2025-32463-sudo-chwoot

PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability

★ 25 · 2025-07-05
zinzloun/CVE-2025-32463

# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so

★ 14 · 2025-07-14
AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.

★ 11 · 2025-07-21
CVE-2026-43499
FRESH PoCHOTMULTI PoC
PoCs 158 ★ 1702 Last push 2026-10-09 (16 hours, 28 minutes ago)

Fetching description from NVD…

Show 8 of 158 repositories
YuKongA/ghostlock-app

GhostLock One-Tap Execution App (CVE-2026-43499)

★ 1702 · 2026-10-08
BuSung-dev/Root-My-Galaxy

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

★ 1381 · 2026-09-03
alex193a/Root-My-Pixel

Jailbreak supported Google Pixel phones with CVE-2026-43499

★ 429 · 2026-09-13
JoinChang/ghostlock-oneplus

GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader

★ 400 · 2026-09-17
x-spy/CVE-2026-43499-popsicle

CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k

★ 251 · 2026-07-15
hmascs/KSuRoot

KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…

★ 235 · 2026-10-02
MobiusM/CVE-2026-43499

CVE-2026-43499 PoC

★ 160 · 2026-06-27
Linuxoid-cn/CVE-2026-43499-Poc-Analysis

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

★ 108 · 2026-07-30
CVE-2021-44228
FRESH PoCHOTMULTI PoC
PoCs 456 ★ 3426 Last push 2026-10-09 (17 hours, 47 minutes ago)

Fetching description from NVD…

Show 8 of 456 repositories
fullhunt/log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

★ 3426 · 2022-11-23
kozmer/log4j-shell-poc

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

★ 1846 · 2024-02-12
christophetd/log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

★ 1141 · 2024-04-26
Puliczek/CVE-2021-44228-PoC-log4j-bypass-words

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

★ 950 · 2022-01-15
logpresso/CVE-2021-44228-Scanner

Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228

★ 862 · 2022-04-07
f0ng/log4j2burpscanner

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

★ 841 · 2023-06-13
mergebase/log4j-detector

A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…

★ 640 · 2022-03-10
corretto/hotpatch-for-apache-log4j2

An agent to hotpatch the log4j RCE from CVE-2021-44228.

★ 497 · 2022-10-24
CVE-2026-64561
FRESH PoCMULTI PoC
PoCs 8 ★ 3 Last push 2026-10-09 (18 hours, 12 minutes ago)

Fetching description from NVD…

Show 8 repositories
HORKimhab/CVE-2026-64561

CVE-2026-64561

★ 3 · 2026-08-07
aarif450/Zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

★ 2 · 2026-10-09
HackSpeak/CVE-2026-64561

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing

★ 2 · 2026-08-08
Aoripus-LTD/Zapscape-Fix

Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)

★ 1 · 2026-08-07
suominen/zapscape

Tracking Zapscape (CVE-2026-64561), the KVM/x86 shadow-MMU guest-to-host escape

★ 0 · 2026-09-27
aarif450/aarif450.github.io

Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.

★ 0 · 2026-08-09
chuzhongyun/CVE-2026-64561-Kernel-Fix

Linux 内核升级指南 - 修复 CVE-2026-64561

★ 0 · 2026-08-08
hitechcloud-vietnam/Zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

★ 0 · 2026-10-03
CVE-2026-88771
CRITICALFRESH PoCMULTI PoC
CVSS 9.5 CRITICAL CWE-20 Published 2026-09-27 PoCs 12 ★ 23 Last push 2026-10-09 (18 hours, 15 minutes ago)

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Show 8 of 12 repositories
ThomasPoppelgaard/netscaler-ctx697096-checker

Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…

★ 18 · 2026-10-08
technion/netscaler_scanner

Tooling related to CVE-2026-88771 and CVE-2026-88772

★ 1 · 2026-10-09
grupooruss/netscaler-defensive-checker

Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778

★ 1 · 2026-10-08
EXEcution-py/CVE-2026-88771-POC

Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total

★ 0 · 2026-09-28
techupdate24/citrix-netscaler-cve-2026-88771-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-28
SwiftSecur/CVE-2026-88771-HuntScript

A detection/hunting script for compromise related to CVE-2026-88771

★ 0 · 2026-09-29
CVE-2026-24291
FRESH PoCMULTI PoC
PoCs 5 ★ 4 Last push 2026-10-09 (18 hours, 27 minutes ago)

Fetching description from NVD…

Show 5 repositories
lennertdefauw/CVE-2026-24291

Windows privilege escalation using RegPwn

★ 4 · 2026-03-19
tracyliving606/RegPwn

Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions

★ 4 · 2026-10-09
n0isegat3/RegPwnBRc4BOF

Brute Ratel C4 BOF of the CVE-2026-24291

★ 3 · 2026-03-18
ZeroDayVPN/CVE-2026-24291

About 2026 Guide: Bypass User Account Control Prompts on Windows 11

★ 1 · 2026-07-12
uname1able/CVE-2026-24291
★ 0 · 2026-03-26
CVE-2026-20841
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 141 Last push 2026-10-09 (18 hours, 33 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
BTtea/CVE-2026-20841-PoC

PoC

★ 141 · 2026-02-11
patchpoint/CVE-2026-20841
★ 12 · 2026-02-12
atiilla/CVE-2026-20841
★ 5 · 2026-02-12
tangent65536/CVE-2026-20841

PoC for the "Windows Notepad RCE"

★ 2 · 2026-02-11
dogukankurnaz/CVE-2026-20841-PoC

CVE-2026-20841

★ 2 · 2026-02-12
hamzamalik3461/CVE-2026-20841

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

★ 1 · 2026-10-09
SecureWithUmer/CVE-2026-20841

PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…

★ 1 · 2026-02-12
CVE-2024-21762
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 150 Last push 2026-10-09 (18 hours, 51 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
h4x0r-dz/CVE-2024-21762

out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability

★ 150 · 2024-03-16
BishopFox/cve-2024-21762-check

Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762

★ 107 · 2024-07-05
r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check

Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)

★ 16 · 2025-06-29
d0rb/CVE-2024-21762

The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.

★ 12 · 2024-03-17
abrewer251/CVE-2024-21762_FortiNet_PoC

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

★ 4 · 2025-05-22
rdoix/cve-2024-21762-checker
★ 1 · 2024-06-20
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
deFr0ggy/CVE-2024-21762-Checker

This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…

★ 0 · 2024-03-25
CVE-2023-27997
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 134 Last push 2026-10-09 (18 hours, 51 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
BishopFox/CVE-2023-27997-check

Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing

★ 134 · 2024-05-08
lexfo/xortigate-cve-2023-27997

xortigate-cve-2023-27997

★ 63 · 2023-10-12
rio128128/CVE-2023-27997-POC

POC FortiOS SSL-VPN buffer overflow vulnerability

★ 27 · 2023-06-16
delsploit/CVE-2023-27997
★ 9 · 2023-10-12
TechinsightsPro/ShodanFortiOS

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

★ 2 · 2023-07-11
imbas007/CVE-2023-27997-Check
★ 1 · 2023-06-23
abraxas/Fortigate-SSL-VPN-Exploit-Kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

★ 1 · 2026-09-01
puckiestyle/cve-2023-27997
★ 0 · 2023-06-23
CVE-2022-40684
FRESH PoCHOTMULTI PoC
PoCs 31 ★ 358 Last push 2026-10-09 (18 hours, 51 minutes ago)

Fetching description from NVD…

Show 8 of 31 repositories
horizon3ai/CVE-2022-40684

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 358 · 2022-10-13
carlosevieira/CVE-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

★ 87 · 2022-10-13
arsolutioner/fortigate-belsen-leak

Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group

★ 87 · 2025-01-16
Filiplain/Fortinet-PoC-Auth-Bypass

Bash PoC for Fortinet Auth Bypass - CVE-2022-40684

★ 16 · 2023-04-02
kljunowsky/CVE-2022-40684-POC

Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

★ 16 · 2023-01-21
TaroballzChen/CVE-2022-40684-metasploit-scanner

An authentication bypass using an alternate path or channel in Fortinet product

★ 14 · 2022-10-27
hughink/CVE-2022-40684
★ 11 · 2022-10-28
qingsiweisan/CVE-2022-40684
★ 9 · 2022-10-26
CVE-2018-13379
FRESH PoCHOTMULTI PoC
PoCs 14 ★ 253 Last push 2026-10-09 (18 hours, 51 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
milo2012/CVE-2018-13379

CVE-2018-13379

★ 253 · 2019-08-14
Blazz3/cve2018-13379-nmap-script

CVE-2018-13379 Script for Nmap NSE.

★ 12 · 2020-09-09
Zeop-CyberSec/fortios_vpnssl_traversal_leak

This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download Forti…

★ 9 · 2021-02-26
B1anda0/CVE-2018-13379

Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本

★ 9 · 2020-12-14
0xHunter/FortiOS-Credentials-Disclosure

CVE-2018-13379 Exploit

★ 6 · 2019-09-24
k4nfr3/CVE-2018-13379-Fortinet

FortiVuln

★ 6 · 2020-11-19
jpiechowka/at-doom-fortigate

Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.

★ 5 · 2024-01-23
Zierax/CVE-2018-13379

CVE-2018-13379 fortiOS vulnerability POC

★ 2 · 2026-02-15
CVE-2026-41089
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 231 Last push 2026-10-09 (20 hours, 3 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
0xABCD01/CVE-2026-41089

Netlogon and CLDAP vulnerability research with a proof of concept.

★ 231 · 2026-06-02
SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

★ 67 · 2026-09-11
HydraSoft/CVE-2026-41089-Netlogon-RCE

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …

★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…

★ 14 · 2026-06-04
hnytgl/CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

★ 13 · 2026-09-26
0xBlackash/CVE-2026-41089

CVE-2026-41089

★ 11 · 2026-06-05
ZeroDayVPN/CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…

★ 5 · 2026-09-29
opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

★ 1 · 2026-10-08
CVE-2026-45585
FRESH PoCMULTI PoC
PoCs 11 ★ 7 Last push 2026-10-09 (20 hours, 8 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
Desireeontrial76/yellowkey-bitlocker

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

★ 7 · 2026-10-09
andrei-majer/bitlocker-hardening

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

★ 5 · 2026-05-24
YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own.…

★ 3 · 2026-09-27
everest90909/YellowKey-WinRE-Remediation

Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…

★ 1 · 2026-05-21
0xBlackash/CVE-2026-45585

CVE-2026-45585

★ 1 · 2026-05-31
bjbakker1984/Yellowkey-mitigation

A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions

★ 0 · 2026-05-20
ChanderManiPandey2022/Yellow-Key-Check

YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)

★ 0 · 2026-06-04
ChanderManiPandey2022/YellowKey-BitLocker-Bypass-CVE-2026-45585-Detect-Fix-Automatically-via-Microsoft-Intune

YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune

★ 0 · 2026-06-08
CVE-2019-7238
FRESH PoCHOTMULTI PoC
PoCs 7 ★ 154 Last push 2026-10-09 (20 hours, 9 minutes ago)

Fetching description from NVD…

Show 7 repositories
mpgn/CVE-2019-7238

🐱‍💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱‍💻

★ 154 · 2019-02-25
jas502n/CVE-2019-7238

Nexus Repository Manager 3 Remote Code Execution without authentication < 3.15.0

★ 85 · 2019-08-19
verctor/nexus_rce_CVE-2019-7238

Some debug notes and exploit(not blind)

★ 39 · 2019-07-28
magicming200/CVE-2019-7238_Nexus_RCE_Tool

CVE-2019-7238 Nexus RCE漏洞图形化一键检测工具。CVE-2019-7238 Nexus RCE Vul POC Tool.

★ 24 · 2020-01-15
DannyRavi/nmap-scripts

nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327

★ 2 · 2025-04-20
smallpiggy/CVE-2019-7238

RCE

★ 1 · 2021-05-20
CyberCTF/vulhub-nexus-cve-2019-7238

Vulhub nexus/CVE-2019-7238: Nexus Repository Manager 3 JEXL Injection RCE (CVE-2019-7238), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-3129
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 289 Last push 2026-10-09 (20 hours, 10 minutes ago)

Fetching description from NVD…

Show 8 of 33 repositories
ambionics/laravel-exploits

Exploit for CVE-2021-3129

★ 289 · 2021-01-29
zhzyker/CVE-2021-3129

Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)

★ 166 · 2021-12-14
joshuavanderpoll/CVE-2021-3129

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

★ 158 · 2026-05-21
SNCKER/CVE-2021-3129

Laravel debug rce

★ 134 · 2021-01-24
nth347/CVE-2021-3129_exploit

Exploit for CVE-2021-3129

★ 69 · 2021-03-07
crisprss/Laravel_CVE-2021-3129_EXP
★ 18 · 2021-01-27
ajisai-babu/CVE-2021-3129-exp

Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp

★ 13 · 2023-03-04
CVE-2026-10520
FRESH PoCMULTI PoC
PoCs 8 ★ 13 Last push 2026-10-09 (20 hours, 12 minutes ago)

Fetching description from NVD…

Show 8 repositories
0xBlackash/CVE-2026-10520

CVE-2026-10520

★ 4 · 2026-06-11
HORKimhab/CVE-2026-10520-10523

CVE-2026-10520 and CVE-2026-10523

★ 0 · 2026-06-11
error-inside/CVE-2026-10520

Root-Level RCE via OS Command Injection in Ivanti Sentry

★ 0 · 2026-06-18
gduma-phData/patch-CVE-2026-10520

Patch: OGNL injection (Apache Struts)

★ 0 · 2026-08-24
01xJB/CVE-2026-10520-POC

Exploit for CVE-2026-10520 | Ivanti Sentry - OS Command Injection

★ 0 · 2026-10-09
CVE-2026-23744
FRESH PoCMULTI PoC
PoCs 40 ★ 12 Last push 2026-10-09 (20 hours, 13 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …

★ 12 · 2026-06-14
suljov/CVE-2026-23744-Remote-Code-Execution-POC

MCPJam inspector contains a remote code execution

★ 12 · 2026-03-22
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in version…

★ 6 · 2026-07-14
FrenzisRed/CVE-2026-23744

CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC

★ 4 · 2026-03-23
luiskrnr/exploit-CVE-2026-23744

MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…

★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …

★ 3 · 2026-08-11
InzegoSec/CVE-2026-23744

Exploit to MCPJam Inspector <=1.4.2

★ 1 · 2026-03-25
ctzisme/CVE-2026-23744

PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).

★ 1 · 2026-03-26
CVE-2026-31431
FRESH PoCHOTMULTI PoC
PoCs 325 ★ 4074 Last push 2026-10-09 (20 hours, 14 minutes ago)

Fetching description from NVD…

Show 8 of 325 repositories
theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

★ 4074 · 2026-04-29
tgies/copy-fail-c

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

★ 445 · 2026-07-17
badsectorlabs/copyfail-go

A Go implementation of copyfail (CVE-2026-31431)

★ 360 · 2026-05-01
Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…

★ 191 · 2026-05-07
Sndav/CVE-2026-31431-Advanced-Exploit

CVE-2026-31431 纯文件利用

★ 111 · 2026-04-30
painoob/Copy-Fail-Exploit-CVE-2026-31431

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …

★ 109 · 2026-04-29
sgkdev/page_inject

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

★ 76 · 2026-05-06
Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)

★ 63 · 2026-05-03
CVE-2019-15107
FRESH PoCMULTI PoC
PoCs 42 ★ 66 Last push 2026-10-09 (20 hours, 31 minutes ago)

Fetching description from NVD…

Show 8 of 42 repositories
jas502n/CVE-2019-15107

CVE-2019-15107 Webmin RCE (unauthorized)

★ 66 · 2019-09-02
MuirlandOracle/CVE-2019-15107
★ 56 · 2024-06-01
hannob/webminex

poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)

★ 8 · 2019-12-25
n0obit4/Webmin_1.890-POC

CVE-2019-15107 exploit

★ 7 · 2020-11-19
ruthvikvegunta/CVE-2019-15107

Webmin <=1.920 RCE

★ 6 · 2020-08-12
AdministratorGithub/CVE-2019-15107

CVE-2019-15107 webmin python3

★ 5 · 2019-08-23
AleWong/WebminRCE-EXP-CVE-2019-15107-

Remote Code Execution Vulnerability in Webmin

★ 3 · 2019-11-01
squid22/Webmin_CVE-2019-15107

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

★ 3 · 2020-10-15
CVE-2020-14882
FRESH PoCHOTMULTI PoC
PoCs 37 ★ 4291 Last push 2026-10-09 (20 hours, 31 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…

★ 4291 · 2021-04-04
jas502n/CVE-2020-14882

CVE-2020–14882、CVE-2020–14883

★ 288 · 2020-11-16
GGyao/CVE-2020-14882_ALL

CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。

★ 145 · 2022-03-29
s1kr10s/CVE-2020-14882

CVE-2020–14882 by Jang

★ 29 · 2020-10-29
NS-Sp4ce/CVE-2020-14882

CVE-2020-14882/14883/14750

★ 19 · 2020-11-04
XTeam-Wing/CVE-2020-14882

CVE-2020-14882 Weblogic-Exp

★ 17 · 2020-10-29
adm1in/CodeTest

CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。

★ 13 · 2020-12-29
GGyao/CVE-2020-14882_POC

CVE-2020-14882批量验证工具。

★ 12 · 2020-12-01
CVE-2017-10271
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 515 Last push 2026-10-09 (20 hours, 31 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
shack2/javaserializetools

Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。

★ 515 · 2020-10-01
c0mmand3rOpSec/CVE-2017-10271

WebLogic Exploit

★ 140 · 2018-07-13
kkirsche/CVE-2017-10271

Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)

★ 128 · 2022-09-16
7kbstorm/WebLogic_CNVD_C2019_48814

WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm

★ 115 · 2019-04-25
SkyBlueEternal/CNVD-C-2019-48814-CNNVD-201904-961

CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC

★ 105 · 2019-04-29
1337g/CVE-2017-10271

CVE-2017-10271 WEBLOGIC RCE (TESTED)

★ 39 · 2017-12-23
Cymmetria/weblogic_honeypot

WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …

★ 33 · 2020-04-25
Luffin/CVE-2017-10271

CVE-2017-10271 POC

★ 29 · 2018-01-10
CVE-2020-13942
FRESH PoCMULTI PoC
PoCs 9 ★ 28 Last push 2026-10-09 (20 hours, 31 minutes ago)

Fetching description from NVD…

Show 8 of 9 repositories
eugenebmx/CVE-2020-13942

CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection

★ 28 · 2020-12-21
shifa123/CVE-2020-13942-POC-

CVE-2020-13942 POC + Automation Script

★ 9 · 2020-11-23
lp008/CVE-2020-13942
★ 6 · 2020-11-19
yaunsky/Unomi-CVE-2020-13942

CVE-2020-13942 Apache Unomi 远程代码执行漏洞脚getshell

★ 4 · 2020-12-22
blackmarketer/CVE-2020-13942
★ 3 · 2022-10-12
dev-team-12x/apche_unomi_rce

Apache Unomi CVE-2020-13942: RCE Vulnerabilities

★ 0 · 2021-01-12
Prodrious/CVE-2020-13942
★ 0 · 2021-09-05
Page 1 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.