Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
CVE-2025-41249
CVE-2024-36774
CVE-2022-21812
8 contacts in last 24h
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
803 results
PoCs 10
★ 73
Last push 2026-10-09 (13 hours, 55 minutes ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 26
★ 430
Last push 2026-10-09 (14 hours, 15 minutes ago)
Fetching description from NVD…
Show 8 of 26 repositories
abdozkaya/rsc-security-auditor
🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…
★ 5 · 2025-12-13
PoCs 19
★ 345
Last push 2026-10-09 (14 hours, 23 minutes ago)
Fetching description from NVD…
Show 8 of 19 repositories
Zain3311/CVE-2025-49844
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
★ 2 · 2026-10-09
ksnnd32/redis_exploit
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
★ 1 · 2026-10-09
PoCs 69
★ 529
Last push 2026-10-09 (14 hours, 27 minutes ago)
Fetching description from NVD…
Show 8 of 69 repositories
1xPwn/CVE-2025-32463
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
★ 26 · 2026-08-12
PoCs 158
★ 1702
Last push 2026-10-09 (16 hours, 28 minutes ago)
Fetching description from NVD…
Show 8 of 158 repositories
hmascs/KSuRoot
KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…
★ 235 · 2026-10-02
PoCs 456
★ 3426
Last push 2026-10-09 (17 hours, 47 minutes ago)
Fetching description from NVD…
Show 8 of 456 repositories
fullhunt/log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
★ 3426 · 2022-11-23
f0ng/log4j2burpscanner
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
★ 841 · 2023-06-13
mergebase/log4j-detector
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…
★ 640 · 2022-03-10
PoCs 8
★ 3
Last push 2026-10-09 (18 hours, 12 minutes ago)
Fetching description from NVD…
Show 8 repositories
aarif450/Zapscape
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
★ 2 · 2026-10-09
HackSpeak/CVE-2026-64561
Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing
★ 2 · 2026-08-08
suominen/zapscape
Tracking Zapscape (CVE-2026-64561), the KVM/x86 shadow-MMU guest-to-host escape
★ 0 · 2026-09-27
aarif450/aarif450.github.io
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
★ 0 · 2026-08-09
hitechcloud-vietnam/Zapscape
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
★ 0 · 2026-10-03
CVSS 9.5 CRITICAL
CWE-20
Published 2026-09-27
PoCs 12
★ 23
Last push 2026-10-09 (18 hours, 15 minutes ago)
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Show 8 of 12 repositories
PoCs 5
★ 4
Last push 2026-10-09 (18 hours, 27 minutes ago)
Fetching description from NVD…
Show 5 repositories
tracyliving606/RegPwn
Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions
★ 4 · 2026-10-09
PoCs 14
★ 141
Last push 2026-10-09 (18 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
SecureWithUmer/CVE-2026-20841
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…
★ 1 · 2026-02-12
PoCs 13
★ 150
Last push 2026-10-09 (18 hours, 51 minutes ago)
Fetching description from NVD…
Show 8 of 13 repositories
d0rb/CVE-2024-21762
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
★ 12 · 2024-03-17
deFr0ggy/CVE-2024-21762-Checker
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…
★ 0 · 2024-03-25
PoCs 12
★ 134
Last push 2026-10-09 (18 hours, 51 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 31
★ 358
Last push 2026-10-09 (18 hours, 51 minutes ago)
Fetching description from NVD…
Show 8 of 31 repositories
horizon3ai/CVE-2022-40684
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
★ 358 · 2022-10-13
PoCs 14
★ 253
Last push 2026-10-09 (18 hours, 51 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
jpiechowka/at-doom-fortigate
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
★ 5 · 2024-01-23
PoCs 12
★ 231
Last push 2026-10-09 (20 hours, 3 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
HydraSoft/CVE-2026-41089-Netlogon-RCE
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …
★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…
★ 14 · 2026-06-04
hnytgl/CVE-2026-41089
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
★ 13 · 2026-09-26
ZeroDayVPN/CVE-2026-41089-Netlogon
🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…
★ 5 · 2026-09-29
PoCs 11
★ 7
Last push 2026-10-09 (20 hours, 8 minutes ago)
Fetching description from NVD…
Show 8 of 11 repositories
everest90909/YellowKey-WinRE-Remediation
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…
★ 1 · 2026-05-21
PoCs 7
★ 154
Last push 2026-10-09 (20 hours, 9 minutes ago)
Fetching description from NVD…
Show 7 repositories
mpgn/CVE-2019-7238
🐱💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱💻
★ 154 · 2019-02-25
PoCs 33
★ 289
Last push 2026-10-09 (20 hours, 10 minutes ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 8
★ 13
Last push 2026-10-09 (20 hours, 12 minutes ago)
Fetching description from NVD…
Show 8 repositories
PoCs 40
★ 12
Last push 2026-10-09 (20 hours, 13 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …
★ 12 · 2026-06-14
luiskrnr/exploit-CVE-2026-23744
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…
★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …
★ 3 · 2026-08-11
ctzisme/CVE-2026-23744
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
★ 1 · 2026-03-26
PoCs 325
★ 4074
Last push 2026-10-09 (20 hours, 14 minutes ago)
Fetching description from NVD…
Show 8 of 325 repositories
tgies/copy-fail-c
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
★ 445 · 2026-07-17
painoob/Copy-Fail-Exploit-CVE-2026-31431
Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …
★ 109 · 2026-04-29
sgkdev/page_inject
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
★ 76 · 2026-05-06
PoCs 42
★ 66
Last push 2026-10-09 (20 hours, 31 minutes ago)
Fetching description from NVD…
Show 8 of 42 repositories
hannob/webminex
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
★ 8 · 2019-12-25
PoCs 37
★ 4291
Last push 2026-10-09 (20 hours, 31 minutes ago)
Fetching description from NVD…
Show 8 of 37 repositories
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…
★ 4291 · 2021-04-04
adm1in/CodeTest
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。
★ 13 · 2020-12-29
PoCs 30
★ 515
Last push 2026-10-09 (20 hours, 31 minutes ago)
Fetching description from NVD…
Show 8 of 30 repositories
shack2/javaserializetools
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
★ 515 · 2020-10-01
Cymmetria/weblogic_honeypot
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …
★ 33 · 2020-04-25
PoCs 9
★ 28
Last push 2026-10-09 (20 hours, 31 minutes ago)
Fetching description from NVD…
Show 8 of 9 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.