Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2009-2265
MULTI PoC
PoCs 7 ★ 2 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 7 repositories
zaphoxx/zaphoxx-coldfusion

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

★ 2 · 2020-10-02
h3x0v3rl0rd/CVE-2009-2265
★ 1 · 2025-06-05
p1ckzi/CVE-2009-2265

cf8-upload.py | CVE-2009-2265

★ 1 · 2022-06-30
0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265

Adobe ColdFusion 8 - Remote Command Execution (RCE)

★ 1 · 2025-01-07
nika0x38/CVE-2009-2265

A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.

★ 0 · 2025-09-27
matesz44/CVE-2009-2265

posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)

★ 0 · 2026-01-12
hd-exe/CVE-2009-2265-fix

fix for not working exploit script on exploitdb (50057.py)

★ 0 · 2026-09-15
CVE-2024-36401
HOTMULTI PoC
PoCs 22 ★ 122 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 8 of 22 repositories
whitebear-ch/GeoServerExploit

GeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具

★ 122 · 2025-01-17
Chocapikk/CVE-2024-36401

GeoServer Remote Code Execution

★ 88 · 2025-04-06
Mr-xn/CVE-2024-36401

Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit

★ 56 · 2024-07-06
ahisec/geoserver-

geoserver CVE-2024-36401漏洞利用工具

★ 45 · 2024-07-24
bmth666/GeoServer-Tools-CVE-2024-36401

CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现

★ 42 · 2026-06-08
bigb0x/CVE-2024-36401

POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.

★ 35 · 2024-07-04
Niuwoo/CVE-2024-36401

POC

★ 4 · 2024-07-05
justin-p/geoexplorer

Mass scanner for CVE-2024-36401

★ 4 · 2024-08-27
CVE-2017-11882
HOTMULTI PoC
PoCs 33 ★ 534 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 8 of 33 repositories
Ridter/CVE-2017-11882

CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882

★ 534 · 2017-11-29
embedi/CVE-2017-11882

Proof-of-Concept exploits for CVE-2017-11882

★ 494 · 2017-11-29
rip1s/CVE-2017-11882

CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.

★ 330 · 2017-12-06
rxwx/CVE-2018-0802

PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)

★ 270 · 2018-02-28
Ridter/RTF_11882_0802

PoC for CVE-2018-0802 And CVE-2017-11882

★ 166 · 2018-01-12
0x09AL/CVE-2017-11882-metasploit

This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-did…

★ 98 · 2017-11-21
starnightcyber/CVE-2017-11882

CVE-2017-11882 exploitation

★ 44 · 2017-11-28
BlackMathIT/2017-11882_Generator

CVE-2017-11882 File Generator PoC

★ 34 · 2017-11-22
CVE-2026-60004
MULTI PoC
PoCs 11 ★ 16 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
imbas007/CVE-2026-60004-POC

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

★ 16 · 2026-08-03
HORKimhab/CVE-2026-60004

CVE-2026-60004

★ 5 · 2026-07-29
0xBlackash/CVE-2026-60004

CVE-2026-60004

★ 5 · 2026-07-30
HackSpeak/CVE-2026-60004

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

★ 2 · 2026-08-04
gagaltotal/CVE-2026-60004-poc-gitea

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

★ 2 · 2026-08-08
EQSTLab/CVE-2026-60004

Gitea diffpatch RCE

★ 1 · 2026-08-19
yym8538/CVE-2026-60004
★ 1 · 2026-08-21
shinthink/CVE-2026-60004

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

★ 0 · 2026-08-03
CVE-2021-4034
HOTMULTI PoC
PoCs 182 ★ 2044 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 182 repositories
berdav/CVE-2021-4034

CVE-2021-4034 1day

★ 2044 · 2022-06-08
ly4k/PwnKit

Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation

★ 1331 · 2022-06-21
arthepsy/CVE-2021-4034

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

★ 1165 · 2023-05-04
PwnFunction/CVE-2021-4034

Proof of concept for pwnkit vulnerability

★ 352 · 2023-01-12
joeammond/CVE-2021-4034

Python exploit code for CVE-2021-4034 (pwnkit)

★ 180 · 2022-01-28
dzonerzy/poc-cve-2021-4034

PoC for CVE-2021-4034 dubbed pwnkit

★ 114 · 2022-01-27
luijait/PwnKit-Exploit

Proof of Concept (PoC) CVE-2021-4034

★ 98 · 2022-02-07
Rvn0xsy/CVE-2021-4034

CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation

★ 96 · 2022-01-28
CVE-2022-0847
HOTMULTI PoC
PoCs 109 ★ 1133 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 109 repositories
Arinerron/CVE-2022-0847-DirtyPipe-Exploit

A root exploit for CVE-2022-0847 (Dirty Pipe)

★ 1133 · 2022-03-08
AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits

A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.

★ 735 · 2023-05-20
r1is/CVE-2022-0847

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…

★ 282 · 2023-02-02
Al1ex/CVE-2022-0847

CVE-2022-0847

★ 91 · 2022-03-09
DataDog/dirtypipe-container-breakout-poc

Container Excape PoC for CVE-2022-0847 "DirtyPipe"

★ 77 · 2022-04-20
basharkey/CVE-2022-0847-dirty-pipe-checker

Bash script to check for CVE-2022-0847 "Dirty Pipe"

★ 72 · 2023-06-14
ZZ-SOCMAP/CVE-2022-0847

Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.

★ 58 · 2022-03-08
bbaranoff/CVE-2022-0847

CVE-2022-0847

★ 50 · 2022-03-07
CVE-2024-27198
HOTMULTI PoC
PoCs 19 ★ 154 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 19 repositories
W01fh4cker/CVE-2024-27198-RCE

CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4

★ 154 · 2024-03-11
yoryio/CVE-2024-27198

Exploit for CVE-2024-27198 - TeamCity Server

★ 37 · 2024-12-19
Stuub/RCity-CVE-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

★ 35 · 2024-07-19
Chocapikk/CVE-2024-27198

Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4

★ 34 · 2024-03-05
passwa11/CVE-2024-27198-RCE
★ 3 · 2024-03-08
geniuszly/CVE-2024-27198

is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)

★ 3 · 2024-10-09
ptd200110/CVE-2024-27198-SOC-Lab
★ 2 · 2026-06-19
CharonDefalt/CVE-2024-27198-RCE
★ 1 · 2024-03-09
CVE-2019-9053
MULTI PoC
PoCs 46 ★ 11 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 46 repositories
4nner/CVE-2019-9053

CVE-2019-9053 Exploit for Python 3

★ 11 · 2023-05-09
Mahamedm/CVE-2019-9053-Exploit-Python-3

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

★ 8 · 2025-02-10
Dh4nuJ4/SimpleCTF-UpdatedExploit

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= …

★ 6 · 2024-06-20
h3x0v3rl0rd/CVE-2019-9053
★ 3 · 2025-06-05
JagdeepSinghCeh/cms-made-simple-python3

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved…

★ 2 · 2025-11-15
d3athcod3/46635.py_CVE-2019-9053

This is modified code of 46635 exploit from python2 to python3.

★ 1 · 2021-05-14
CVE-2024-25600
HOTMULTI PoC
PoCs 19 ★ 183 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 19 repositories
Chocapikk/CVE-2024-25600

Unauthenticated Remote Code Execution – Bricks <= 1.9.6

★ 183 · 2024-02-25
Christbowel/CVE-2024-25600_Nuclei-Template

Nuclei template and information about the POC for CVE-2024-25600

★ 31 · 2024-02-21
so1icitx/CVE-2024-25600

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

★ 13 · 2026-09-13
Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticate…

★ 8 · 2024-02-22
X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE

WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)

★ 1 · 2024-04-20
estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC

Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication,…

★ 1 · 2026-02-19
CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file u…

★ 1 · 2026-07-16
svchostmm/CVE-2024-25600-mass
★ 0 · 2024-05-05
CVE-2025-48384
MULTI PoC
PoCs 42 ★ 53 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 42 repositories
acheong08/CVE-2025-48384

Breaking git with a carriage return and cloning RCE

★ 53 · 2025-07-08
liamg/CVE-2025-48384

PoC for CVE-2025-48384

★ 20 · 2025-07-09
vinieger/vinieger-CVE-2025-48384-Dockerfile

PoC dockerfile image for CVE-2025-48384

★ 1 · 2025-07-11
IK-20211125/CVE-2025-48384

CVE-2025-48384 PoC

★ 1 · 2025-07-21
zr0n/CVE-2025-48384-sub
★ 1 · 2025-12-04
zr0n/CVE-2025-48384-main

A proof of concept of remote code execution

★ 1 · 2025-12-04
fishyyh/CVE-2025-48384

for CVE-2025-48384 test

★ 0 · 2025-07-09
CVE-2025-38352
HOTMULTI PoC
PoCs 6 ★ 311 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 6 repositories
farazsth98/chronomaly

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

★ 311 · 2026-01-05
farazsth98/poc-CVE-2025-38352

This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin menti…

★ 117 · 2026-01-05
AnalyticETH/chronomaly-webos

CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibl…

★ 17 · 2026-06-01
jordelmir/Elysium-Vanguard-Sentinel-Audit

The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.

★ 2 · 2026-02-24
Crime2/poc-CVE-2025-38352
★ 0 · 2026-01-08
longwasu/CVE-2025-38352-PoC

PoC and GDB script assists in triggering CVE-2025-38352

★ 0 · 2026-09-13
CVE-2013-2028
MULTI PoC
PoCs 8 ★ 54 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 repositories
kitctf/nginxpwn

Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow

★ 54 · 2016-03-23
danghvu/nginx-1.4.0

For the analysis of CVE-2013-2028

★ 30 · 2018-06-07
m4drat/CVE-2013-2028-Exploit

CVE-2013-2028 python exploit

★ 19 · 2020-06-27
tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC

this is not stable

★ 2 · 2019-08-03
jptr218/nginxhack

A CVE-2013-2028 implementation

★ 1 · 2021-07-27
Sunqiz/CVE-2013-2028-reproduction

CVE-2013-2028复现

★ 0 · 2022-08-15
xiw1ll/CVE-2013-2028_Checker

Tool for checking Nginx CVE-2013-2028

★ 0 · 2024-07-23
vanivamshi/CVE-2013-2028-Exploit
★ 0 · 2026-09-13
CVE-2026-50751
MULTI PoC
PoCs 8 ★ 6 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 repositories
WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts

Mitigation scripts for CVE-2026-50751

★ 1 · 2026-06-13
0xBlackash/CVE-2026-50751

CVE-2026-50751

★ 1 · 2026-06-08
fevar54/CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit

PoC de CVE-2026-50751: bypass de autenticacion IKEv1 en Check Point Remote/Mobile Access.

★ 1 · 2026-06-10
WadesWeaponShed/CheckPoint-CVE-Webscanner

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using Check Point…

★ 1 · 2026-09-11
uLl0a/CVE-2026-50751

Bypass de autenticación por certificado en la VPN Remote-Access de Check Point (IKEv1).

★ 1 · 2026-09-13
fernstedt/CVE-2026-50751

CVE-2026-50751 Check Point IKEv1 vulnerability scanner

★ 0 · 2026-06-10
e4zyy/Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

★ 0 · 2026-08-28
CVE-2023-1326
MULTI PoC
PoCs 5 ★ 21 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 5 repositories
diego-tella/CVE-2023-1326-PoC

A proof of concept for CVE-2023–1326 in apport-cli 2.26.0

★ 21 · 2023-12-06
h3x0v3rl0rd/CVE-2023-1326
★ 1 · 2024-05-04
Pol-Ruiz/CVE-2023-1326

Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326

★ 0 · 2024-01-26
cve-2024/CVE-2023-1326-PoC
★ 0 · 2024-06-14
R3fr4kt/DEVVORTEX

A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enu…

★ 0 · 2026-09-12
CVE-2022-38181
MULTI PoC
PoCs 6 ★ 7 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 6 repositories
Pro-me3us/CVE_2022_38181_Raven

CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)

★ 7 · 2024-12-03
ericpardee/fire-hd-ownership

Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog

★ 6 · 2026-08-24
Pro-me3us/CVE_2022_38181_Gazelle

CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)

★ 4 · 2023-06-29
R0rt1z2/CVE-2022-38181
★ 3 · 2023-07-03
artur9010/amazon-mustang-hack

FireOS 7.3.3.1 temp root by CVE-2022-38181

★ 0 · 2026-09-12
CVE-2026-21858
HOTMULTI PoC
PoCs 17 ★ 303 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 8 of 17 repositories
Chocapikk/CVE-2026-21858

n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

★ 303 · 2026-03-26
ZeroDayEvil/CVE-2026-21858-n8n-FullChain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…

★ 88 · 2026-09-12
sh4den/CVE-2026-21858

Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.

★ 3 · 2026-07-06
cropnet/Ni8mare

Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0) without perform…

★ 2 · 2026-01-12
sec-dojo-com/CVE-2026-21858
★ 1 · 2026-01-20
EQSTLab/CVE-2026-21858

Ni8mare, n8n RCE

★ 1 · 2026-05-20
0xBlackash/CVE-2026-21858

CVE-2026-21858

★ 1 · 2026-03-05
Fomovet/cve-2026-21858

POC for CVE-2026-21858

★ 1 · 2026-06-21
CVE-2025-68613
HOTMULTI PoC
PoCs 36 ★ 105 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 8 of 36 repositories
wioui/n8n-CVE-2025-68613-exploit

CVE-2025-68613: n8n RCE vulnerability exploit and documentation

★ 105 · 2025-12-23
ZeroDayEvil/CVE-2026-21858-n8n-FullChain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…

★ 88 · 2026-09-12
TheStingR/CVE-2025-68613-POC

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, f…

★ 29 · 2025-12-26
rxerium/CVE-2025-68613

Detection for CVE-2025-68613

★ 27 · 2025-12-22
LingerANR/n8n-CVE-2025-68613

This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.

★ 7 · 2025-12-26
hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

★ 5 · 2025-12-25
mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613

Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection

★ 2 · 2025-12-25
JohannesLks/CVE-2025-68613-Python-Exploit

Python Exploit for CVE-2025-68613.

★ 1 · 2026-02-14
CVE-2026-20805
MULTI PoC
PoCs 6 ★ 92 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 6 repositories
ZeroDayEvil/CVE-2026-20805-PoC

🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic).

★ 92 · 2026-09-11
fevar54/CVE-2026-20805-POC

PoC de CVE-2026-20805: divulgacion de informacion en Desktop Window Manager (dwm.exe) de Windows.

★ 7 · 2026-01-14
Uzair-Baig0900/CVE-2026-20805-PoC

The PoC of information disclosure in Microsoft Desktop Windows Management.

★ 2 · 2026-01-19
SimoesCTT/-SCTT-2026-33-0002-DWM-Visual-Field-Singularity

### 📡 Theoretical Classification **ID:** SCTT-2026-33-0002 **Researcher:** Americo Simoes (SimoesCTT) **Physics:** Theorem 4.2 - Turbulent Phase Transition…

★ 1 · 2026-01-31
mrk336/Inside-CVE-2026-20805-How-a-Windows-DWM-Flaw-Exposed-Sensitive-Data

CVE‑2026‑20805: A Windows Desktop Window Manager flaw causing local information disclosure. Requires low privileges, no user interaction. Rated CVSS 5.5 (Mediu…

★ 0 · 2026-01-28
SimoesCTT/SCTT-2026-33-0002-DWM-Visual-Field-Singularity

Microsoft just patched CVE-2026-20805 and CVE-2026-20871 in January 2026 to stop "Information Disclosure" and "Use-After-Free" bugs in DWM. They think they've …

★ 0 · 2026-01-31
CVE-2017-7921
HOTMULTI PoC
PoCs 23 ★ 116 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 23 repositories
chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor

This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.

★ 116 · 2021-01-29
JrDw0/CVE-2017-7921-EXP

Hikvision camera CVE-2017-7921-EXP

★ 102 · 2023-12-04
BurnyMcDull/CVE-2017-7921

海康威视未授权访问检测poc及口令爆破

★ 35 · 2020-11-19
voidsshadows/Hikvision-City-Hunter

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, …

★ 19 · 2025-11-19
MisakaMikato/cve-2017-7921-golang

Hikvision IP camera access bypass exploit, developed by golang.

★ 13 · 2026-03-17
Th3Purge/CVE-2017-7921-Exploit

Exploit for CVE-2017-7921, targeting the improper authentication vulnerability affecting Hikvision camera systems.

★ 9 · 2026-09-11
kooroshsanaei/HikVision-CVE-2017-7921

Test For CVE-2017–7921;

★ 7 · 2024-07-02
alkaid176/CVE-2017-7921

CVE-2017-7921-EXP Hikvision camera

★ 6 · 2022-07-20
CVE-2023-23397
HOTMULTI PoC
PoCs 29 ★ 345 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 29 repositories
sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY

Exploit for the CVE-2023-23397

★ 158 · 2023-03-15
Trackflaw/CVE-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

★ 132 · 2023-03-24
ka7ana/CVE-2023-23397

Simple PoC in PowerShell for CVE-2023-23397

★ 40 · 2023-03-16
tiepologian/CVE-2023-23397

Proof of Concept for CVE-2023-23397 in Python

★ 25 · 2023-03-21
BronzeBee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

★ 14 · 2023-03-22
djackreuter/CVE-2023-23397-PoC
★ 9 · 2023-03-18
CVE-2025-3248
MULTI PoC
PoCs 27 ★ 17 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 27 repositories
ynsmroztas/CVE-2025-3248-Langflow-RCE

CVE-2025-3248 Langflow RCE Exploit

★ 17 · 2025-06-17
xuemian168/CVE-2025-3248

A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。

★ 11 · 2025-04-10
verylazytech/CVE-2025-3248
★ 10 · 2025-04-16
0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

★ 7 · 2025-06-23
PuddinCat/CVE-2025-3248-POC

POC of CVE-2025-3248, RCE of LangFlow

★ 3 · 2025-04-10
dennisec/Mass-CVE-2025-3248

Mass-CVE-2025-3248

★ 3 · 2025-06-23
EQSTLab/CVE-2025-3248

Langflow Remote Code Execution

★ 3 · 2025-09-17
drackyjr/cve-2025-3248-exploit

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…

★ 3 · 2025-11-21
CVE-2022-24637
MULTI PoC
PoCs 7 ★ 5 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
Lay0us/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3

★ 5 · 2022-08-30
hupe1980/CVE-2022-24637

Open Web Analytics (OWA) - Unauthenticated Remote Code Execution

★ 5 · 2022-10-12
icebreack/CVE-2022-24637

FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)

★ 4 · 2022-11-15
Pflegusch/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution

★ 4 · 2023-04-08
0xM4hm0ud/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

★ 3 · 2023-03-26
0xRyuk/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

★ 1 · 2023-08-22
PrinceAikinsBaidoo/CVE-2022-24637
★ 0 · 2026-09-10
CVE-2026-66066
MULTI PoC
PoCs 7 ★ 30 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
Zer0SumGam3/CVE-2026-66066-POC

PoC for CVE-2026-66066 in Ruby on Rails

★ 23 · 2026-07-30
0xsha/KindaRails2Shell

CVE-2026-66066 + File Read, RCE, Scanner, Lab

★ 4 · 2026-07-31
HackSpeak/CVE-2026-66066

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

★ 4 · 2026-08-04
0xBlackash/CVE-2026-66066

CVE-2026-66066

★ 1 · 2026-07-31
shinthink/CVE-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged vari…

★ 1 · 2026-08-04
ivanesk315/CVE-2026-66066
★ 0 · 2026-09-10
CVE-2026-20253
MULTI PoC
PoCs 7 ★ 13 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-20253

CVE-2026-20253

★ 5 · 2026-06-13
HORKimhab/CVE-2026-20253

CVE-2026-20253 - Splunk Enterprise

★ 0 · 2026-06-14
fevar54/CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-

PoC de CVE-2026-20253: RCE pre-autenticacion en Splunk Enterprise.

★ 0 · 2026-06-26
pssec-io/CVE-2026-20253

POC for CVE-2026-20253

★ 0 · 2026-06-29
Het-Kalariya/CVE-2026-20253
★ 0 · 2026-07-18
ivanesk315/CVE-2026-20253
★ 0 · 2026-09-10
CVE-2023-25157
HOTMULTI PoC
PoCs 10 ★ 165 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 8 of 10 repositories
win3zz/CVE-2023-25157

CVE-2023-25157 - GeoServer SQL Injection - PoC

★ 165 · 2023-07-14
murataydemir/CVE-2023-25157-and-CVE-2023-25158

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)

★ 13 · 2023-06-11
0x2458bughunt/CVE-2023-25157
★ 10 · 2023-06-10
7imbitz/CVE-2023-25157-checker

A script, written in golang. POC for CVE-2023-25157

★ 3 · 2024-02-02
charis3306/CVE-2023-25157

CVE-2023-25157 exp

★ 3 · 2025-04-24
dr-cable-tv/Geoserver-CVE-2023-25157

Geoserver SQL Injection Exploit

★ 2 · 2023-11-28
Rubikcuv5/CVE-2023-25157

GeoServer OGC Filter SQL Injection Vulnerabilities

★ 0 · 2023-07-31
custiya/geoserver-CVE-2023-25157
★ 0 · 2025-04-21
< Prev Page 10 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.