Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
350PoC updated in 7 days
filters
803 results
PoCs 17
★ 44
Last push 2026-09-05 (1 month ago)
Fetching description from NVD…
Show 8 of 17 repositories
PoCs 5
★ 1
Last push 2026-09-04 (1 month ago)
Fetching description from NVD…
Show 5 repositories
PoCs 15
★ 83
Last push 2026-09-04 (1 month ago)
Fetching description from NVD…
Show 8 of 15 repositories
Catherines77/ActiveMQ-EXPtools
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
★ 83 · 2026-06-27
keraattin/CVE-2026-34197
CVE-2026-34197: Apache ActiveMQ Classic RCE via Jolokia API (CVSS 8.8). Python & Nmap NSE detection scripts. A 13-year-old vulnerability allows remote code exe…
★ 2 · 2026-04-14
PoCs 6
★ 19
Last push 2026-09-04 (1 month ago)
Fetching description from NVD…
Show 6 repositories
AnggaTechI/CVE-2026-63077
CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass exploitation t…
★ 0 · 2026-08-08
0xCyp1337/CVE-2026-63077
CVE-2026-63077 - Unauthenticated RCE exploit for JetBrains TeamCity via Agent Polling Deserialization. Supports mass scanning, multi-threading, and interactive…
★ 0 · 2026-09-04
PoCs 28
★ 802
Last push 2026-09-03 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 28 repositories
byt3bl33d3r/ItWasAllADream
A PrintNightmare (CVE-2021-34527) Python Scanner. Scan entire subnets for hosts vulnerable to the PrintNightmare RCE
★ 802 · 2024-05-19
CVSS 9.8 CRITICAL
CWE-94
Published 2026-07-17
PoCs 8
★ 3
Last push 2026-09-02 (1 month, 1 week ago)
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Show 8 repositories
PoCs 5
★ 7
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
Nxploited/CVE-2026-0920-
LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter
★ 3 · 2026-04-18
PoCs 8
★ 1
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 repositories
PoCs 8
★ 4
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 repositories
EQSTLab/CVE-2026-5027
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal
★ 3 · 2026-04-24
min8282/CVE-2026-5027
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)
★ 0 · 2026-04-03
PoCs 10
★ 31
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 14
★ 319
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 7
★ 230
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 7 repositories
xcanwin/CVE-2023-4357-Chrome-XXE
[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
★ 230 · 2025-04-04
PoCs 6
★ 193
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 6 repositories
PoCs 20
★ 442
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 20 repositories
inspiringz/CVE-2021-3493
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
★ 42 · 2021-07-07
Ayham-Megdadi/Zero-Day-Legacy
A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hi…
★ 2 · 2026-07-05
PoCs 7
★ 50
Last push 2026-08-31 (1 month, 1 week ago)
Fetching description from NVD…
Show 7 repositories
r4ch1d0/CVE-2018-14667_Lab_POC
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
★ 0 · 2026-08-31
PoCs 6
★ 4
Last push 2026-08-31 (1 month, 1 week ago)
Fetching description from NVD…
Show 6 repositories
symphony2colour/varlib-cve-2025-66034
Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, …
★ 2 · 2026-08-31
4nuxd/CVE-2025-66034
CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.
★ 0 · 2026-03-28
PoCs 5
★ 83
Last push 2026-08-31 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
Catherines77/ActiveMQ-EXPtools
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
★ 83 · 2026-06-27
PoCs 26
★ 50
Last push 2026-08-30 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 26 repositories
win3zz/CVE-2025-5777
CVE-2025-5777 (CitrixBleed 2) - Critical memory leak vulnerability affecting Citrix NetScaler ADC and Gateway devices
★ 50 · 2025-07-08
nocerainfosec/cve-2025-5777
Memory disclosure vulnerability in Citrix NetScaler ADC and Gateway when configured as a Gateway (VPN virtual server, ICA proxy, CVPN, RDP Proxy).
★ 3 · 2025-07-06
cyberleelawat/ExploitVeer
An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the vulnerability but…
★ 3 · 2025-07-17
PoCs 10
★ 17
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 5
★ 48
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
PoCs 9
★ 487
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 9 repositories
LSinus/CacheMeIfYouCan
SLUBStick exploitation of CVE-2022-2588. Converting a DF into a cross-cache arbitrary memory R/W primitive through PTE manipulation.
★ 2 · 2026-08-29
PoCs 10
★ 5
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
dinosn/CVE-2026-3844
CVE-2026-3844: Breeze Cache <= 2.4.4 Unauthenticated Arbitrary File Upload to RCE (CVSS 9.8)
★ 5 · 2026-04-25
tausifzaman/CVE-2026-3844
PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.
★ 3 · 2026-04-24
AnggaTechI/CVE-2026-3844
CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-thr…
★ 2 · 2026-08-08
im-hanzou/CVE-2026-3844
Breeze Cache WordPress <=2.4.4 allows unauthenticated file upload via fetch_gravatar_from_remote when local gravatar hosting is enabled.
★ 0 · 2026-04-24
PoCs 10
★ 6
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
samael0x4/CVE-2026-21962
Unauthenticated vulnerability that may allow remote attackers to compromise confidentiality and integrity, potentially leading to full system compromise.
★ 6 · 2026-01-22
PoCs 5
★ 58
Last push 2026-08-29 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
l0ggg/CVE-2026-55040
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
★ 3 · 2026-07-28
PoCs 14
★ 57
Last push 2026-08-28 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
monke443/CVE-2023-27350
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the SetupCompleted Java …
★ 4 · 2025-03-09
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.