Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
351PoC updated in 7 days
filters
803 results
PoCs 7
★ 2
Last push 2026-09-15 (3 weeks, 4 days ago)
Fetching description from NVD…
Show 7 repositories
nika0x38/CVE-2009-2265
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
★ 0 · 2025-09-27
PoCs 22
★ 122
Last push 2026-09-15 (3 weeks, 4 days ago)
Fetching description from NVD…
Show 8 of 22 repositories
Mr-xn/CVE-2024-36401
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
★ 56 · 2024-07-06
bigb0x/CVE-2024-36401
POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.
★ 35 · 2024-07-04
PoCs 33
★ 534
Last push 2026-09-15 (3 weeks, 4 days ago)
Fetching description from NVD…
Show 8 of 33 repositories
0x09AL/CVE-2017-11882-metasploit
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-did…
★ 98 · 2017-11-21
PoCs 11
★ 16
Last push 2026-09-14 (3 weeks, 5 days ago)
Fetching description from NVD…
Show 8 of 11 repositories
shinthink/CVE-2026-60004
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
★ 0 · 2026-08-03
PoCs 182
★ 2044
Last push 2026-09-14 (3 weeks, 5 days ago)
Fetching description from NVD…
Show 8 of 182 repositories
ly4k/PwnKit
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
★ 1331 · 2022-06-21
arthepsy/CVE-2021-4034
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
★ 1165 · 2023-05-04
PoCs 109
★ 1133
Last push 2026-09-14 (3 weeks, 5 days ago)
Fetching description from NVD…
Show 8 of 109 repositories
r1is/CVE-2022-0847
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…
★ 282 · 2023-02-02
PoCs 19
★ 154
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 46
★ 11
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 46 repositories
Dh4nuJ4/SimpleCTF-UpdatedExploit
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= …
★ 6 · 2024-06-20
JagdeepSinghCeh/cms-made-simple-python3
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved…
★ 2 · 2025-11-15
PoCs 19
★ 183
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 19 repositories
so1icitx/CVE-2024-25600
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
★ 13 · 2026-09-13
PoCs 42
★ 53
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 42 repositories
PoCs 6
★ 311
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 6 repositories
farazsth98/chronomaly
Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.
★ 311 · 2026-01-05
farazsth98/poc-CVE-2025-38352
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin menti…
★ 117 · 2026-01-05
AnalyticETH/chronomaly-webos
CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibl…
★ 17 · 2026-06-01
PoCs 8
★ 54
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 repositories
kitctf/nginxpwn
Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow
★ 54 · 2016-03-23
PoCs 8
★ 6
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 repositories
uLl0a/CVE-2026-50751
Bypass de autenticación por certificado en la VPN Remote-Access de Check Point (IKEv1).
★ 1 · 2026-09-13
e4zyy/Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
★ 0 · 2026-08-28
PoCs 5
★ 21
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 5 repositories
R3fr4kt/DEVVORTEX
A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enu…
★ 0 · 2026-09-12
PoCs 6
★ 7
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 17
★ 303
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 8 of 17 repositories
ZeroDayEvil/CVE-2026-21858-n8n-FullChain
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…
★ 88 · 2026-09-12
sh4den/CVE-2026-21858
Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.
★ 3 · 2026-07-06
cropnet/Ni8mare
Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0) without perform…
★ 2 · 2026-01-12
PoCs 36
★ 105
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 8 of 36 repositories
ZeroDayEvil/CVE-2026-21858-n8n-FullChain
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…
★ 88 · 2026-09-12
TheStingR/CVE-2025-68613-POC
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, f…
★ 29 · 2025-12-26
LingerANR/n8n-CVE-2025-68613
This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.
★ 7 · 2025-12-26
PoCs 6
★ 92
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 6 repositories
ZeroDayEvil/CVE-2026-20805-PoC
🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic).
★ 92 · 2026-09-11
PoCs 23
★ 116
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 23 repositories
voidsshadows/Hikvision-City-Hunter
This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, …
★ 19 · 2025-11-19
PoCs 29
★ 345
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 29 repositories
PoCs 27
★ 17
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 27 repositories
xuemian168/CVE-2025-3248
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
★ 11 · 2025-04-10
drackyjr/cve-2025-3248-exploit
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…
★ 3 · 2025-11-21
PoCs 7
★ 5
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 7 repositories
PoCs 7
★ 30
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 7 repositories
HackSpeak/CVE-2026-66066
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
★ 4 · 2026-08-04
shinthink/CVE-2026-66066
CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged vari…
★ 1 · 2026-08-04
PoCs 7
★ 13
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 7 repositories
PoCs 10
★ 165
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 8 of 10 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.