Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
351PoC updated in 7 days
filters
803 results
PoCs 11
★ 10
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 8 of 11 repositories
codeb0ssx/Ultimate-wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…
★ 10 · 2026-07-18
Colere-Sys/wp2shell-poc
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
★ 3 · 2026-07-21
ebrasha/abdal-cve-2026-60137
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. …
★ 2 · 2026-07-24
h4cd0c/wp2shell
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…
★ 0 · 2026-07-18
michael-kanda/Wp2shell-ioc-scanner
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and …
★ 0 · 2026-08-03
PoCs 5
★ 41
Last push 2026-09-10 (1 month ago)
Fetching description from NVD…
Show 5 repositories
oscerd/CVE-2026-40453
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
★ 0 · 2026-07-08
PoCs 14
★ 27
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 8 of 14 repositories
duck-sec/CVE-2023-41425
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
★ 3 · 2024-10-02
PoCs 5
★ 29
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 5 repositories
PoCs 70
★ 321
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 8 of 70 repositories
TAM-K592/CVE-2024-4577
CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.
★ 75 · 2024-06-11
PoCs 7
★ 8
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 7 repositories
spikeyjr/CVE-2023-34468-PoC
Educational proof-of-concept for CVE-2023-34468 affecting Apache NiFi. Demonstrates H2 JDBC URL abuse leading to authenticated RCE in vulnerable NiFi versions.
★ 0 · 2026-06-16
PoCs 5
★ 14
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 5 repositories
TAM-K592/CVE-2025-55752
CVE-2025-55752, Apache Tomcat that allows directory traversal via URL rewrite, and under certain conditions, leads to remote code execution (RCE) if HTTP PUT i…
★ 13 · 2025-10-28
xiaoqiMikko/tomcat85-check
CVE-2025-55752:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5 也受影响」的 2025 CVE 有 14 条,其中 10 条在 NVD 按 8.5.100 查不到。离线单 jar,读 conf/ 判断你到底中了哪几条。
★ 0 · 2026-09-09
PoCs 21
★ 9
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 8 of 21 repositories
tc4dy/CVE-2026-29000-PoC-Exploit
CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, p…
★ 3 · 2026-06-06
PoCs 16
★ 505
Last push 2026-09-09 (1 month ago)
Fetching description from NVD…
Show 8 of 16 repositories
kyotozx/CVE-2024-2961-Remote-File-Read
This script demonstrates a proof-of-concept (PoC) for exploiting a file read vulnerability in the iconv library, as detailed in Ambionics Security's blog https…
★ 5 · 2025-05-07
PoCs 5
★ 16
Last push 2026-09-08 (1 month ago)
Fetching description from NVD…
Show 5 repositories
GhostlyrootB2H/CVE-2026-82222
⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), mul…
★ 0 · 2026-09-08
PoCs 6
★ 9
Last push 2026-09-08 (1 month ago)
Fetching description from NVD…
Show 6 repositories
atiilla/CVE-2026-85046
CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82
★ 9 · 2026-09-08
CVSS 9.8 CRITICAL
CWE-306
Published 2026-05-29
PoCs 6
★ 8
Last push 2026-09-08 (1 month ago)
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.
Show 6 repositories
Jenderal92/CVE-2026-8732
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
★ 3 · 2026-05-31
PoCs 21
★ 393
Last push 2026-09-07 (1 month ago)
Fetching description from NVD…
Show 8 of 21 repositories
chaudharyarjun/LooneyPwner
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
★ 43 · 2023-10-18
PoCs 18
★ 152
Last push 2026-09-07 (1 month ago)
Fetching description from NVD…
Show 8 of 18 repositories
nootropics/propane
Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution
★ 2 · 2015-06-01
PoCs 14
★ 519
Last push 2026-09-07 (1 month ago)
Fetching description from NVD…
Show 8 of 14 repositories
hacker30468/Mikrotik-router-hack
This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerabili…
★ 55 · 2021-04-21
PoCs 6
★ 249
Last push 2026-09-07 (1 month ago)
Fetching description from NVD…
Show 6 repositories
ly4k/BlueGate
PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE
★ 249 · 2020-01-24
ioncodes/BlueGate
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
★ 78 · 2020-01-31
MalwareTech/RDGScanner
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
★ 69 · 2020-01-26
PoCs 21
★ 25
Last push 2026-09-06 (1 month ago)
Fetching description from NVD…
Show 8 of 21 repositories
rxerium/CVE-2025-31324
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious ex…
★ 4 · 2025-10-14
PoCs 8
★ 77
Last push 2026-09-06 (1 month ago)
Fetching description from NVD…
Show 8 repositories
ynsmroztas/nextssrf
NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF
★ 77 · 2026-05-15
dinosn/CVE-2026-44578
CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.
★ 9 · 2026-05-16
love07oj/nextjs-cve-2026-44578
Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world sca…
★ 8 · 2026-05-15
PoCs 5
★ 3
Last push 2026-09-06 (1 month ago)
Fetching description from NVD…
Show 5 repositories
xxconi/CVE-2026-6279
CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via …
★ 0 · 2026-06-11
PoCs 18
★ 245
Last push 2026-09-06 (1 month ago)
Fetching description from NVD…
Show 8 of 18 repositories
duy-31/CVE-2023-7028
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5…
★ 3 · 2024-01-12
PoCs 5
★ 36
Last push 2026-09-06 (1 month ago)
Fetching description from NVD…
Show 5 repositories
PoCs 6
★ 41
Last push 2026-09-05 (1 month ago)
Fetching description from NVD…
Show 6 repositories
aninfosec/CVE-2025-1094
It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject ma…
★ 1 · 2025-06-26
skraft9/CVE-2024-12356
Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)
★ 1 · 2026-09-05
PoCs 5
★ 5
Last push 2026-09-05 (1 month ago)
Fetching description from NVD…
Show 5 repositories
Jenderal92/CVE-2026-56290
CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploade…
★ 5 · 2026-07-08
shinthink/pbck-exploit
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
★ 3 · 2026-07-04
ChiefYoru/CVE-2026-56290_PoC
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
★ 0 · 2026-07-19
PoCs 9
★ 21
Last push 2026-09-05 (1 month ago)
Fetching description from NVD…
Show 8 of 9 repositories
shinthink/CVE-2026-3891
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
★ 4 · 2026-07-21
willygailo/CVE-2026-3891-Linux
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions …
★ 2 · 2026-05-31
Ch4120N/CVE-2026-3891
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
★ 2 · 2026-08-03
VeronnX666/CVE-2026-3891
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
★ 0 · 2026-07-19
PoCs 6
★ 12
Last push 2026-09-05 (1 month ago)
Fetching description from NVD…
Show 6 repositories
4minx/CVE-2026-32475
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
★ 1 · 2026-09-05
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.