Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-60137
MULTI PoC
PoCs 11 ★ 10 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 8 of 11 repositories
codeb0ssx/Ultimate-wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…

★ 10 · 2026-07-18
Colere-Sys/wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

★ 3 · 2026-07-21
ebrasha/abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. …

★ 2 · 2026-07-24
h4cd0c/wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…

★ 0 · 2026-07-18
mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

★ 0 · 2026-07-21
northsia/CVE-2026-60137-With-Skip-SSL

Adding --insecure to skip ssl

★ 0 · 2026-07-26
michael-kanda/Wp2shell-ioc-scanner

Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and …

★ 0 · 2026-08-03
CVE-2025-27636
MULTI PoC
PoCs 5 ★ 41 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 5 repositories
Crystallen1/CVE-2025-27636-demo
★ 0 · 2025-10-23
oscerd/CVE-2026-40453

Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)

★ 0 · 2026-07-08
AC8999/CVE-2025-27636-RCE-in-Apache-Camel

CVE-2025-27636 PoC written in Python

★ 0 · 2026-09-10
CVE-2023-41425
MULTI PoC
PoCs 14 ★ 27 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 14 repositories
prodigiousMind/CVE-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

★ 27 · 2024-12-30
Tea-On/CVE-2023-41425-RCE-WonderCMS-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderC…

★ 8 · 2025-07-16
thefizzyfish/CVE-2023-41425-wonderCMS_RCE

CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script …

★ 3 · 2024-10-03
duck-sec/CVE-2023-41425

CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.

★ 3 · 2024-10-02
charlesgargasson/CVE-2023-41425

Wonder CMS RCE (XSS)

★ 1 · 2024-08-11
Raffli-Dev/CVE-2023-41425
★ 1 · 2024-09-03
Diegomjx/CVE-2023-41425-WonderCMS-Authenticated-RCE

Xss injection, WonderCMS 3.2.0 -3.4.2

★ 1 · 2026-09-09
xpltive/CVE-2023-41425

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

★ 1 · 2024-12-23
CVE-2023-6063
MULTI PoC
PoCs 5 ★ 29 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 5 repositories
motikan2010/CVE-2023-6063-PoC

CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)

★ 29 · 2023-11-15
Eulex0x/CVE-2023-6063

CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)

★ 9 · 2023-11-16
incommatose/CVE-2023-6063-PoC

A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.

★ 2 · 2025-07-16
hackersroot/CVE-2023-6063-PoC

Exploiting SQL Injection Vulnerability in WP Fastest Cache (CVE-2023-6063)

★ 0 · 2023-11-16
zhairiazzeddine/Exploit-CVE-2023-6063-PoC-Vuln

CVE-2023-6063-PoC Exploit

★ 0 · 2026-09-09
CVE-2024-4577
HOTMULTI PoC
PoCs 70 ★ 321 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 70 repositories
watchtowrlabs/CVE-2024-4577

PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC

★ 321 · 2024-06-22
xcanwin/CVE-2024-4577-PHP-RCE

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

★ 160 · 2024-07-21
TAM-K592/CVE-2024-4577

CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.

★ 75 · 2024-06-11
Night-have-dreams/php-cgi-Injector

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

★ 52 · 2025-03-29
11whoami99/CVE-2024-4577

POC & $BASH script for CVE-2024-4577

★ 43 · 2024-06-09
Chocapikk/CVE-2024-4577

PHP CGI Argument Injection vulnerability

★ 35 · 2026-01-24
ZephrFish/CVE-2024-4577-PHP-RCE

PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template

★ 33 · 2026-07-30
gh-ost00/CVE-2024-4577-RCE

PHP CGI Argument Injection (CVE-2024-4577) RCE

★ 25 · 2024-08-20
CVE-2023-34468
MULTI PoC
PoCs 7 ★ 8 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 7 repositories
mbadanoiu/CVE-2023-34468

CVE-2023-34468: Remote Code Execution via DB Components in Apache NiFi

★ 8 · 2023-12-01
sbouabid-sec/CVE-2023-34468-POC

PoC exploit for CVE-2023-34468 — RCE via H2 RUNSCRIPT in Apache NiFi <= 1.21.0

★ 4 · 2026-05-10
Jeanpt/CVE-2023-34468

CVE-2023-34468 - Apache NiFi H2 RCE PoC

★ 1 · 2026-05-10
spikeyjr/CVE-2023-34468-PoC

Educational proof-of-concept for CVE-2023-34468 affecting Apache NiFi. Demonstrates H2 JDBC URL abuse leading to authenticated RCE in vulnerable NiFi versions.

★ 0 · 2026-06-16
ozcanpng/CVE-2023-34468

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC

★ 0 · 2026-07-12
luiskrnr/HTB_Helix_CVE-2023-34468

Writeup of the Hackthebox Helix machine

★ 0 · 2026-09-09
CVE-2025-55752
MULTI PoC
PoCs 5 ★ 14 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 5 repositories
masahiro331/CVE-2025-55752
★ 14 · 2025-10-31
TAM-K592/CVE-2025-55752

CVE-2025-55752, Apache Tomcat that allows directory traversal via URL rewrite, and under certain conditions, leads to remote code execution (RCE) if HTTP PUT i…

★ 13 · 2025-10-28
AuroraSec-Pivot/CVE-2025-55752

基于 Docker 的重现环境,用于复现 Apache Tomcat 10.1.44 中的路径遍历漏洞 CVE-2025-55752。本实验场景可以复现官网报道的RCE

★ 2 · 2025-11-05
Jimmy01240397/CVE-2025-55752
★ 0 · 2026-02-19
xiaoqiMikko/tomcat85-check

CVE-2025-55752:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5 也受影响」的 2025 CVE 有 14 条,其中 10 条在 NVD 按 8.5.100 查不到。离线单 jar,读 conf/ 判断你到底中了哪几条。

★ 0 · 2026-09-09
CVE-2026-29000
MULTI PoC
PoCs 21 ★ 9 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
kernelzeroday/CVE-2026-29000

pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs

★ 9 · 2026-03-06
Strikoder-Premium/CVE-2026-29000-pac4j-jwt

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

★ 3 · 2026-05-03
tc4dy/CVE-2026-29000-PoC-Exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, p…

★ 3 · 2026-06-06
RootX111/cve-2026-29000

cve-2026-29000 exploit

★ 2 · 2026-03-16
manbahadurthapa1248/CVE-2026-29000---pac4j-jwt-Authentication-Bypass-PoC

CVE-2026-29000 - pac4j-jwt Authentication Bypass PoC

★ 1 · 2026-03-13
otuva/CVE-2026-29000
★ 1 · 2026-03-13
PtechAmanja/CVE-2026-29000-pac4j-jwt-auth-bypass

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

★ 1 · 2026-03-24
CVE-2024-2961
HOTMULTI PoC
PoCs 16 ★ 505 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 16 repositories
ambionics/cnext-exploits

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()

★ 505 · 2024-09-30
rvzsec/CVE-2024-2961

CVE-2024–2961 Security Issue Mitigation Script

★ 5 · 2024-05-20
kyotozx/CVE-2024-2961-Remote-File-Read

This script demonstrates a proof-of-concept (PoC) for exploiting a file read vulnerability in the iconv library, as detailed in Ambionics Security's blog https…

★ 5 · 2025-05-07
suce0155/CVE-2024-2961

CVE-2024-2961 Cnext RCE Exploit with Buddyforms 2.7.7

★ 4 · 2025-02-04
mattaperkins/FIX-CVE-2024-2961

Quick mitigation script

★ 2 · 2024-04-24
kjdfklha/CVE-2024-2961_poc
★ 2 · 2024-06-04
omarelshopky/exploit_cve-2023-26326_using_cve-2024-2961

Exploit for CVE-2023-26326 in the WordPress BuddyForms plugin, leveraging CVE-2024-2961 for remote code execution. This exploit bypasses PHP 8+ deserialization…

★ 1 · 2025-02-02
absolutedesignltd/iconvfix

Bash script to patch for CVE-2024-2961

★ 0 · 2024-05-30
CVE-2026-82222
MULTI PoC
PoCs 5 ★ 16 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 5 repositories
dinosn/givewp-cve-2026-82222-rce-lab

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

★ 16 · 2026-08-30
UdinChan/cve-2026-82222-poc

Public PoC for CVE-2026-82222

★ 1 · 2026-08-30
R0x19/CVE-2026-82222

GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE

★ 0 · 2026-08-31
GhostlyrootB2H/CVE-2026-82222

⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), mul…

★ 0 · 2026-09-08
CVE-2026-85046
MULTI PoC
PoCs 6 ★ 9 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 6 repositories
atiilla/CVE-2026-85046

CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82

★ 9 · 2026-09-08
adriyansyah-mf/cve-2026-85046-poc
★ 6 · 2026-09-05
HORKimhab/CVE-2026-85046

CVE-2026-85046

★ 1 · 2026-09-04
ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine

Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine

★ 0 · 2026-09-04
Eliot-code/CVE-2026-85046
★ 0 · 2026-09-07
CVE-2026-8732
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-306 Published 2026-05-29 PoCs 6 ★ 8 Last push 2026-09-08 (1 month ago)

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Show 6 repositories
p3Nt3st3r-sTAr/CVE-2026-8732-POC
★ 8 · 2026-06-01
zycoder0day/CVE-2026-8732

CVE-2026-8732 | WP Maps Pro <= 6.1.0 | Unauthenticated Privilege Escalation

★ 3 · 2026-05-30
Jenderal92/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

★ 3 · 2026-05-31
fientix/CVE-2026-8732-PoC

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

★ 2 · 2026-09-08
xShadow-Here/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation

★ 1 · 2026-05-30
HORKimhab/CVE-2026-8732

CVE-2026-8732 - Draft (WordPress)

★ 0 · 2026-06-01
CVE-2023-4911
HOTMULTI PoC
PoCs 21 ★ 393 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
leesh3288/CVE-2023-4911

PoC for CVE-2023-4911

★ 393 · 2023-10-04
RickdeJager/CVE-2023-4911

CVE-2023-4911 proof of concept

★ 167 · 2023-10-08
chaudharyarjun/LooneyPwner

Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.

★ 43 · 2023-10-18
ruycr4ft/CVE-2023-4911

CVE-2023-4911

★ 19 · 2023-10-11
KernelKrise/CVE-2023-4911

Looney Tunables Local privilege escalation (CVE-2023-4911) workshop

★ 18 · 2024-10-01
Green-Avocado/CVE-2023-4911

https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt

★ 15 · 2023-10-05
Diego-AltF4/CVE-2023-4911

Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit

★ 8 · 2024-11-03
CVE-2015-3306
HOTMULTI PoC
PoCs 18 ★ 152 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 8 of 18 repositories
t0kx/exploit-CVE-2015-3306

ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

★ 152 · 2018-04-07
nootropics/propane

Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution

★ 2 · 2015-06-01
xyk0x/cpx_proftpd

Tool for exploit CVE-2015-3306

★ 1 · 2015-04-22
davidtavarez/CVE-2015-3306

ProFTPd 1.3.5 - File Copy

★ 1 · 2017-07-29
cd6629/CVE-2015-3306-Python-PoC

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

★ 1 · 2020-12-24
0xm4ud/ProFTPD_CVE-2015-3306
★ 1 · 2021-06-07
jptr218/proftpd_bypass

An implementation of CVE-2015-3306

★ 1 · 2021-08-21
cybersensei-EH/hackviser_labs_CVE-2015-3306

This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.

★ 1 · 2025-11-02
CVE-2018-14847
HOTMULTI PoC
PoCs 14 ★ 519 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 8 of 14 repositories
BasuCert/WinboxPoC

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

★ 519 · 2020-10-16
hacker30468/Mikrotik-router-hack

This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerabili…

★ 55 · 2021-04-21
jas502n/CVE-2018-14847

MikroTik RouterOS Winbox未经身份验证的任意文件读/写漏洞

★ 30 · 2018-12-16
sinichi449/Python-MikrotikLoginExploit

PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script

★ 21 · 2019-09-30
syrex1013/MikroRoot

Automated version of CVE-2018-14847 (MikroTik Exploit)

★ 15 · 2025-06-12
msterusky/WinboxExploit

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

★ 7 · 2018-09-11
mahmoodsabir/mikrotik-beast

Mass MikroTik WinBox Exploitation tool, CVE-2018-14847

★ 6 · 2019-05-26
babyshen/routeros-CVE-2018-14847-bytheway

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

★ 4 · 2022-11-17
CVE-2020-0609
HOTMULTI PoC
PoCs 6 ★ 249 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 6 repositories
ly4k/BlueGate

PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE

★ 249 · 2020-01-24
ioncodes/BlueGate

PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610

★ 78 · 2020-01-31
MalwareTech/RDGScanner

A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.

★ 69 · 2020-01-26
ruppde/rdg_scanner_cve-2020-0609

Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)

★ 39 · 2020-07-05
Archi73ct/CVE-2020-0609
★ 2 · 2020-01-28
Bhanunamikaze/BlueGate-CVE-2020-0609

BlueGate Exploit validator - RD Gateway validator for CVE-2020-0609 and CVE-2020-0610 (BlueGate) using OpenSSL DTLS over UDP/3391.

★ 0 · 2026-09-07
CVE-2025-31324
MULTI PoC
PoCs 21 ★ 25 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
redrays-io/CVE-2025-31324

CVE-2025-31324, SAP Exploit

★ 25 · 2025-04-28
antichainalysis/sap-netweaver-0day-CVE-2025-31324

sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324

★ 22 · 2025-08-15
Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

★ 9 · 2025-06-06
NULLTRACE0X/CVE-2025-31324
★ 9 · 2025-05-12
ODST-Forge/CVE-2025-31324_PoC

Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader

★ 7 · 2025-04-28
rf-peixoto/sap_netweaver_cve-2025-31324-

Research Purposes only

★ 5 · 2025-05-07
rxerium/CVE-2025-31324

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious ex…

★ 4 · 2025-10-14
CVE-2026-44578
MULTI PoC
PoCs 8 ★ 77 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 repositories
ynsmroztas/nextssrf

NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF

★ 77 · 2026-05-15
dinosn/CVE-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

★ 9 · 2026-05-16
love07oj/nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world sca…

★ 8 · 2026-05-15
0xBlackash/CVE-2026-44578

CVE-2026-44578

★ 1 · 2026-05-17
lxxexxbxx/CVE-2026-44578

CVE-2026-44578 PoC

★ 1 · 2026-08-20
panchocosil/verify-ghsa-c4j6-fc7j-m34r

OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)

★ 0 · 2026-05-13
tocong282/CVE-2026-44578-PoC
★ 0 · 2026-05-15
isaca0315/CVE-2026-44578-next-js-ssrf

este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah

★ 0 · 2026-09-06
CVE-2026-6279
MULTI PoC
PoCs 5 ★ 3 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 5 repositories
zycoder0day/CVE-2026-6279

CVE-2026-6279 — Avada Builder <= 3.15.2 Unauthenticated RCE via call_user_func()

★ 3 · 2026-05-23
87achrafg-stack/CVE-2026-6279.py

CVE-2026-6279

★ 1 · 2026-06-13
xxconi/CVE-2026-6279

CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via …

★ 0 · 2026-06-11
87achrafg-stack/CVE-2026-6279
★ 0 · 2026-06-13
katranSefa/CVE-2026-6279
★ 0 · 2026-09-06
CVE-2023-7028
HOTMULTI PoC
PoCs 18 ★ 245 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 of 18 repositories
Vozec/CVE-2023-7028

This repository presents a proof-of-concept of CVE-2023-7028

★ 245 · 2024-01-13
RandomRobbieBF/CVE-2023-7028

CVE-2023-7028

★ 58 · 2024-01-12
Esonhugh/gitlab_honeypot

CVE-2023-7028 killer

★ 4 · 2024-01-18
duy-31/CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5…

★ 3 · 2024-01-12
Trackflaw/CVE-2023-7028-Docker

Repository to install CVE-2023-7028 vulnerable Gitlab instance

★ 3 · 2024-01-25
sariamubeen/CVE-2023-7028
★ 3 · 2025-02-17
thanhlam-attt/CVE-2023-7028
★ 2 · 2024-01-23
hackeremmen/gitlab-exploit

GitLab CVE-2023-7028

★ 1 · 2024-01-28
CVE-2025-24799
MULTI PoC
PoCs 5 ★ 36 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 5 repositories
MatheuZSecurity/Exploit-CVE-2025-24799

CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection

★ 36 · 2025-04-15
MuhammadWaseem29/CVE-2025-24799

CVE-2025-24799 SQLi Scanner

★ 5 · 2025-04-03
Rosemary1337/CVE-2025-24799

CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection

★ 0 · 2025-09-08
airbus-cert/CVE-2025-24799-scanner

Scanner for GLPI CVE-2025-24799 vulnerability

★ 0 · 2025-09-16
galisko/CVE-2025-24799
★ 0 · 2026-09-06
CVE-2025-1094
MULTI PoC
PoCs 6 ★ 41 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 6 repositories
soltanali0/CVE-2025-1094-Exploit

WebSocket and SQL Injection Exploit Script

★ 41 · 2025-02-27
aninfosec/CVE-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject ma…

★ 1 · 2025-06-26
skraft9/CVE-2024-12356

Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)

★ 1 · 2026-09-05
PinkArmor/CVE-2025-1094-Lab-Setup
★ 0 · 2025-10-19
TranDongA3/POC-CVE-2025-1094
★ 0 · 2026-05-16
CVE-2026-56290
MULTI PoC
PoCs 5 ★ 5 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 5 repositories
Jenderal92/CVE-2026-56290

CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploade…

★ 5 · 2026-07-08
shinthink/pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

★ 3 · 2026-07-04
sagsooz/PageBuilderCK-CVE-2026-56290-Exploit

Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter

★ 2 · 2026-07-04
ChiefYoru/CVE-2026-56290_PoC

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

★ 0 · 2026-07-19
katranSefa/CVE-2026-56290
★ 0 · 2026-09-05
CVE-2026-3891
MULTI PoC
PoCs 9 ★ 21 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 8 of 9 repositories
m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

★ 21 · 2026-07-20
joshuavanderpoll/CVE-2026-3891

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC

★ 7 · 2026-03-13
Nxploited/CVE-2026-3891

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

★ 6 · 2026-03-27
shinthink/CVE-2026-3891

Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8

★ 4 · 2026-07-21
AnggaTechI/Mass-Scanner-CVE-2026-3891

CVE-2026-3891 Mass Scanning

★ 2 · 2026-04-16
willygailo/CVE-2026-3891-Linux

⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions …

★ 2 · 2026-05-31
Ch4120N/CVE-2026-3891

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

★ 2 · 2026-08-03
VeronnX666/CVE-2026-3891

This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.

★ 0 · 2026-07-19
CVE-2026-32475
MULTI PoC
PoCs 6 ★ 12 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 6 repositories
absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload …

★ 12 · 2026-08-21
dinosn/cve-2026-32475-elementor-pro-lab

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

★ 8 · 2026-09-05
Boreas37/CVE-2026-32475-PoC

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

★ 6 · 2026-08-25
sahmsec/CVE-2026-32475
★ 1 · 2026-08-27
4minx/CVE-2026-32475

CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE

★ 1 · 2026-09-05
0xBlackash/CVE-2026-32475

CVE-2026-32475

★ 0 · 2026-08-22
< Prev Page 11 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.