Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
349PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-20131
MULTI PoC
PoCs 5 ★ 3 Last push 2026-08-28 (1 month, 1 week ago)

Fetching description from NVD…

Show 5 repositories
sak110/CVE-2026-20131
★ 3 · 2026-03-11
Hassan-Pouladi/Cisco-FMC-honeypot

Originally a Honeypot for CVE-2026-20131

★ 2 · 2026-07-03
p3Nt3st3r-sTAr/CVE-2026-20131-POC
★ 0 · 2026-03-18
0xBlackash/CVE-2026-20131

CVE-2026-20131

★ 0 · 2026-05-10
Jwa7470/CVE-2026-20131-Post-Incident-Written-Report

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause an…

★ 0 · 2026-08-28
CVE-2025-43529
HOTMULTI PoC
PoCs 7 ★ 113 Last push 2026-08-27 (1 month, 1 week ago)

Fetching description from NVD…

Show 7 repositories
0xjohnnydev/WebKit-UAF-ANGLE-OOB-Analysis

Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari

★ 113 · 2026-08-27
jir4vv1t/CVE-2025-43529

exploit for cve-2025-43529

★ 86 · 2026-01-05
GenericCoding/pois0nSword

A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1

★ 69 · 2026-08-04
bjrjk/CVE-2025-43529

Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.

★ 18 · 2026-02-01
SimoesCTT/Convergent-Time-Theory-Enhanced-iOS-Safari-RCE-CVE-2025-43529-

CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)

★ 1 · 2026-01-28
SimoesCTT/CTT-Apple-Silicon-Refraction

webkit_refraction.js (The 33-Layer WebGL Payload) ​This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the …

★ 1 · 2026-01-30
kmeps4/bugtest

CVE-2025-43529 Test

★ 1 · 2026-03-02
CVE-2010-1240
MULTI PoC
PoCs 5 ★ 71 Last push 2026-08-27 (1 month, 1 week ago)

Fetching description from NVD…

Show 5 repositories
Jasmoon99/Embedded-PDF

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedd…

★ 71 · 2021-06-06
omarothmann/Embedded-Backdoor-Connection

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedde…

★ 8 · 2022-01-26
asepsaepdin/CVE-2010-1240
★ 1 · 2023-09-03
12345qwert123456/CVE-2010-1240

Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions

★ 0 · 2025-09-17
ocfagb/hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-12…

★ 0 · 2026-08-27
CVE-2025-54068
HOTMULTI PoC
PoCs 6 ★ 152 Last push 2026-08-27 (1 month, 1 week ago)

Fetching description from NVD…

Show 6 repositories
synacktiv/Livepyre

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

★ 152 · 2026-07-16
HelgeSverre/livewire-honeypot

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068, and CVE-20…

★ 6 · 2026-05-15
haxorstars/CVE-2025-54068

A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.

★ 5 · 2026-03-12
e4zyy/Project-CVE-2025-54068

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.

★ 4 · 2026-08-27
flame-11/CVE-2025-54068-livewire
★ 1 · 2026-01-08
luisdalmolin/recon-test-livewire

Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning

★ 0 · 2026-07-07
CVE-2026-19478
MULTI PoC
PoCs 5 ★ 11 Last push 2026-08-27 (1 month, 1 week ago)

Fetching description from NVD…

Show 5 repositories
davkharrr/CVE-2026-19478-PoC

CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer

★ 11 · 2026-08-18
dinosn/gitlab-cve-2026-19478-lab

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

★ 11 · 2026-08-18
EQSTLab/CVE-2026-19478

GitLab Code injection

★ 4 · 2026-08-27
renzi25031469/CVE-2026-19478

Nuclei detection template for CVE-2026-19478, a critical (CVSS 9.4) unauthenticated arbitrary method invocation flaw in the GitLab GraphQL API,

★ 1 · 2026-08-19
n0xdaemon/cve-2026-19478

CVE-2026-19478: GitLab GraphQL Vulnerability PoC

★ 0 · 2026-08-20
CVE-2025-2945
MULTI PoC
PoCs 7 ★ 7 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
Cycloctane/cve-2025-2945-poc

Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)

★ 7 · 2025-11-30
abrewer251/CVE-2025-2945_PgAdmin_PoC

pgAdmin Proof of Concept

★ 3 · 2025-06-03
I3r1h0n/pgAdminOpendoor

Exploit and test stand for CVE-2025-2945

★ 0 · 2025-11-11
plur1bu5/CVE-2025-2945-pgadmin-rce

Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes

★ 0 · 2026-03-16
g0d150ne/CVE-2025-2945

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

★ 0 · 2026-08-10
Khashayarnzk/CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

★ 0 · 2026-08-26
CVE-2025-69212
MULTI PoC
PoCs 13 ★ 4 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 13 repositories
lukasz-rybak/CVE-2025-69212

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

★ 4 · 2026-04-11
tohib09/CVE-2025-69212-PoC
★ 4 · 2026-06-28
BridgerAlderson/CVE-2025-69212-PoC

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

★ 4 · 2026-07-02
c0gnit00/CVE-2026-69212

Python poc, exploit for CVE-2025-69212

★ 2 · 2026-06-28
w3nch/CVE-2025-69212
★ 1 · 2026-06-29
xorandd/CVE-2025-69212-PoC
★ 0 · 2026-07-07
alaeddine03/CVE-2025-69212-PoC

CVE-2025-69212 - OpenSTAManager OS Command Injection PoC

★ 0 · 2026-07-01
m2sousa/CVE-2025-69212

CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.

★ 0 · 2026-07-01
CVE-2018-16763
MULTI PoC
PoCs 24 ★ 27 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 24 repositories
p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

★ 27 · 2025-01-31
padsalatushal/CVE-2018-16763

Fuel CMS 1.4.1 - Remote Code Execution

★ 6 · 2021-11-13
altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE

Fuel CMS 1.4.1 - Remote Code Execution

★ 5 · 2025-01-08
shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--

A working PoC to CVE-2018-16763

★ 3 · 2021-03-07
hikarihacks/CVE-2018-16763-exploit

This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1

★ 2 · 2020-09-03
kxisxr/Bash-Script-CVE-2018-16763

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Executio…

★ 2 · 2021-11-30
h3x0v3rl0rd/CVE-2018-16763
★ 2 · 2025-06-05
CVE-2022-42475
HOTMULTI PoC
PoCs 9 ★ 108 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 9 repositories
scrt/cve-2022-42475

POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon

★ 108 · 2023-03-14
0xhaggis/CVE-2022-42475

An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products

★ 33 · 2023-06-21
P4x1s/CVE-2022-42475-RCE-POC

CVE-2022-42475 飞塔RCE漏洞 POC

★ 8 · 2023-03-23
Amir-hy/cve-2022-42475

FortiOS buffer overflow vulnerability

★ 7 · 2023-03-16
bryanster/ioc-cve-2022-42475

test for the ioc described for FG-IR-22-398

★ 1 · 2023-05-14
uLl0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the S…

★ 1 · 2026-08-25
natceil/cve-2022-42475
★ 0 · 2023-04-27
CVE-2026-50522
MULTI PoC
PoCs 5 ★ 43 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 5 repositories
4minx/CVE-2026-50522

CVE-2026-50522 PoC

★ 43 · 2026-08-15
WismanSec/sharepoint-2026-poc

PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE,…

★ 2 · 2026-08-06
HORKimhab/CVE-2026-50522

CVE-2026-50522

★ 0 · 2026-08-24
ChPratik/CVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

★ 0 · 2026-07-27
darses/CVE-2026-50522

Microsoft SharePoint CVE-2026-50522

★ 0 · 2026-07-30
CVE-2019-0708
HOTMULTI PoC
PoCs 122 ★ 1185 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 122 repositories
Ekultek/BlueKeep

Proof of concept for CVE-2019-0708

★ 1185 · 2026-03-16
robertdavidgraham/rdpscan

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.

★ 921 · 2019-06-22
n1xbyte/CVE-2019-0708

dump

★ 494 · 2019-06-01
k8gege/CVE-2019-0708

3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)

★ 389 · 2019-06-13
algo7/bluekeep_CVE-2019-0708_poc_to_exploit

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

★ 342 · 2021-01-10
cbwang505/CVE-2019-0708-EXP-Windows

CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell

★ 317 · 2020-01-21
0xeb-bp/bluekeep

Public work for CVE-2019-0708

★ 294 · 2019-11-19
Cyb0r9/ispy

ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )

★ 245 · 2021-02-06
CVE-2023-44487
HOTMULTI PoC
PoCs 26 ★ 248 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 26 repositories
bcdannyboy/CVE-2023-44487

Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487

★ 248 · 2024-01-08
secengjeff/rapidresetclient

Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)

★ 76 · 2023-10-30
imabee101/CVE-2023-44487

Proof of concept for DoS exploit

★ 56 · 2023-10-13
studiogangster/CVE-2023-44487

A python based exploit to test out rapid reset attack (CVE-2023-44487)

★ 22 · 2023-10-16
nxenon/cve-2023-44487

Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept

★ 15 · 2023-11-10
ndrscodes/http2-rst-stream-attacker

Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's…

★ 6 · 2024-01-11
ReToCode/golang-CVE-2023-44487
★ 2 · 2023-10-26
CVE-2024-9264
HOTMULTI PoC
PoCs 13 ★ 131 Last push 2026-08-23 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 13 repositories
nollium/CVE-2024-9264

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

★ 131 · 2024-12-16
z3k0sec/CVE-2024-9264-RCE-Exploit

Grafana RCE exploit (CVE-2024-9264)

★ 38 · 2024-10-21
z3k0sec/File-Read-CVE-2024-9264

File Read Proof of Concept for CVE-2024-9264

★ 8 · 2024-10-20
Cythonic1/CVE-2024-9264

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

★ 3 · 2025-06-05
rvzsec/CVE-2024-9264

Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit

★ 2 · 2025-07-07
Exerrdev/CVE-2024-9264-Fixed
★ 0 · 2025-06-15
Royall-Researchers/CVE-2024-9264
★ 0 · 2025-07-05
ruizii/CVE-2024-9264

Grafana RCE

★ 0 · 2025-07-05
CVE-2024-28000
MULTI PoC
PoCs 7 ★ 23 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
Alucard0x1/CVE-2024-28000

LiteSpeed Cache Privilege Escalation PoC

★ 23 · 2024-08-25
arch1m3d/CVE-2024-28000

PoC for the CVE-2024 Litespeed Cache Privilege Escalation

★ 7 · 2025-04-16
ebrasha/CVE-2024-28000

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

★ 5 · 2025-11-06
JohnDoeAnonITA/CVE-2024-28000

CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account

★ 5 · 2025-03-18
SSSSuperX/CVE-2024-28000

CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp

★ 1 · 2024-09-09
AliHzSec/CVE-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environm…

★ 0 · 2026-07-30
shawnng078-ops/CVE-2024-28000-Exploit-Lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery, Administrator pr…

★ 0 · 2026-08-22
CVE-2021-36260
HOTMULTI PoC
PoCs 14 ★ 389 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 14 repositories
tamim1089/HikvisionExploiter

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the W…

★ 389 · 2025-12-22
Aiminsun/CVE-2021-36260

command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability t…

★ 305 · 2021-10-28
Cuerz/CVE-2021-36260

海康威视RCE漏洞 批量检测和利用工具

★ 171 · 2022-08-05
TaroballzChen/CVE-2021-36260-metasploit

the metasploit script(POC) about CVE-2021-36260

★ 20 · 2021-11-03
rabbitsafe/CVE-2021-36260

CVE-2021-36260

★ 17 · 2023-10-27
tuntin9x/CheckHKRCE

CVE-2021-36260

★ 7 · 2022-10-27
sylhetyhackvenger/HIKRAVEN

HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests de…

★ 7 · 2026-08-22
aengussong/hikvision_probe

Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)

★ 3 · 2024-11-26
CVE-2026-0740
MULTI PoC
PoCs 8 ★ 24 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 repositories
0xgh057r3c0n/CVE-2026-0740

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload

★ 24 · 2026-07-18
xShadow-Here/CVE-2026-0740

POC

★ 3 · 2026-04-08
MadExploits/ninja-form-exploit

CVE-2026-0740

★ 3 · 2026-07-14
whattheslime/CVE-2026-0740

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)

★ 2 · 2026-06-12
murrez/CVE-2026-0740

CVE-2026-0740

★ 1 · 2026-04-25
ExDev994/CVE-2026-0740-mass

PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.

★ 1 · 2026-07-11
a24ac1/CVE-2026-0740
★ 0 · 2026-05-20
CVE-2026-26980
MULTI PoC
PoCs 7 ★ 19 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
dinosn/ghost-cve-2026-26980

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

★ 19 · 2026-04-18
gagaltotal/CVE-2026-26980-Ghost-CMS-Api

CVE-2026-26980 - Ghost CMS Content API SQL Injection

★ 11 · 2026-06-26
vognik/CVE-2026-26980

💣 Exploit for CVE-2026-26980 — 👻 Ghost CMS Unauthenticated SQLi via Content API

★ 10 · 2026-08-16
EQSTLab/CVE-2026-26980

Ghost Content API SQL Injection

★ 3 · 2026-05-27
n0bitaemon/CVE-2026-26980-PoC

Ghost CMS Content API Blind SQL Injection

★ 1 · 2026-06-26
yym8538/CVE-2026-26980
★ 1 · 2026-08-21
Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and ed…

★ 0 · 2026-08-21
CVE-2026-2005
MULTI PoC
PoCs 5 ★ 27 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 5 repositories
var77/CVE-2026-2005

PoC for CVE-2026-2005

★ 27 · 2026-05-13
dinosn/cve-2026-2005

CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit

★ 18 · 2026-05-05
M3str3/CVE-2026-2005

PoC for CVE-2026-2005 — heap buffer overflow in PostgreSQL pgcrypto (pgp_pub_decrypt). Oversized PGP session key bypasses bounds check in pgp-pubdec.c. Affects…

★ 0 · 2026-03-07
stvm8/CVE-2026-2005_lab
★ 0 · 2026-05-04
open-flaw/CVE-2026-2005
★ 0 · 2026-08-21
CVE-2026-20896
MULTI PoC
PoCs 7 ★ 10 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
szybnev/cve-2026-20896-gitea-poc

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

★ 10 · 2026-07-07
rz1027/CVE-2026-20896

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

★ 6 · 2026-07-05
XaocZenon/CVE-2026-20896

this is a modified POC of rz1027 for CVE-2026-20896

★ 6 · 2026-07-16
kaleth4/CVE-2026-20896
★ 1 · 2026-07-03
EQSTLab/CVE-2026-20896

Gitea Docker Image Authentication Bypass

★ 1 · 2026-08-04
judgedbykira/CVE-2026-20896-Gitea-Authentication-Bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea …

★ 1 · 2026-08-15
yym8538/CVE-2026-20896
★ 1 · 2026-08-21
CVE-2022-36804
MULTI PoC
PoCs 19 ★ 35 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 19 repositories
notdls/CVE-2022-36804

A real exploit for BitBucket RCE CVE-2022-36804

★ 35 · 2024-08-31
notxesh/CVE-2022-36804-PoC

Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1

★ 18 · 2022-09-19
benjaminhays/CVE-2022-36804-PoC-Exploit

Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

★ 16 · 2023-11-23
sh4den/CVE-2022-36804

A loader for bitbucket 2022 rce (cve-2022-36804)

★ 12 · 2026-07-06
walnutsecurity/cve-2022-36804

A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects a…

★ 8 · 2023-01-25
kljunowsky/CVE-2022-36804-POC

Bitbucket CVE-2022-36804 unauthenticated remote command execution

★ 7 · 2023-01-21
tahtaciburak/cve-2022-36804

A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]

★ 7 · 2022-09-25
ColdFusionX/CVE-2022-36804

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

★ 7 · 2022-10-04
CVE-2026-8181
MULTI PoC
PoCs 12 ★ 6 Last push 2026-08-20 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 12 repositories
zycoder0day/CVE-2026-8181

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

★ 6 · 2026-05-15
murrez/CVE-2026-8181

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports. Authorized…

★ 4 · 2026-05-15
whattheslime/CVE-2026-8181

Exploit for the CVE-2026-8181 - Burst Statistics WordPress Plugin Authentication Bypass

★ 1 · 2026-05-16
xShadow-Here/CVE-2026-8181

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

★ 1 · 2026-05-17
Jenderal92/CVE-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

★ 0 · 2026-05-30
x48ps/CVE-2026-8181

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any inc…

★ 0 · 2026-05-22
Yucaerin/CVE-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

★ 0 · 2026-05-22
CVE-2025-59536
MULTI PoC
PoCs 6 ★ 1 Last push 2026-08-19 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 6 repositories
AetherAI3/AETHER-PROTOCOL-P

Working implementation: cryptographically verified short-lived identities for AI decision authentication — CVE-2025-59536 (Patent Pending US 64/006,746)

★ 1 · 2026-08-19
Rohitberiwala/Claude-Code-MCP-Injection-PoC

Professional PoC for CVE-2025-59536 and related CVEs. Demonstrates an MCP Tool Confirmation Prompt Misrepresentation in Anthropic Claude_Code leading to arbitr…

★ 0 · 2026-03-10
NetVanguard-cmd/CVE-2025-59536
★ 0 · 2026-04-19
TreRB/ai-ide-config-guard

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CV…

★ 0 · 2026-04-20
Razi-Interactive/claude-project-scanner

Read-only safety scanner for Claude Code projects. Catches CVE-2025-59536, statusLine injection, prompt injection, and more.

★ 0 · 2026-04-30
Perufitlife/dotclaude-security

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-2185…

★ 0 · 2026-06-21
CVE-2025-24893
MULTI PoC
PoCs 45 ★ 22 Last push 2026-08-19 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 8 of 45 repositories
gunzf0x/CVE-2025-24893

PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.

★ 22 · 2025-08-22
dollarboysushil/CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POC

CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling …

★ 17 · 2025-08-04
b0ySie7e/CVE-2025-24893
★ 11 · 2025-09-03
iSee857/CVE-2025-24893-PoC

XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)

★ 10 · 2025-04-01
Infinit3i/CVE-2025-24893

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It a…

★ 6 · 2025-09-02
Hex00-0x4/CVE-2025-24893-XWiki-RCE

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch

★ 6 · 2025-08-08
AliElKhatteb/CVE-2024-32019-POC

this is a poc for the CVE-2025-24893

★ 5 · 2025-08-03
hackersonsteroids/cve-2025-24893

Modified exploit for CVE-2025-24893

★ 5 · 2025-08-03
CVE-2026-34486
MULTI PoC
PoCs 5 ★ 69 Last push 2026-08-19 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 5 repositories
striga-ai/CVE-2026-34486

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

★ 69 · 2026-05-11
AirSkye/CVE-2026-34486-poc

CVE-2026-34486 Apache Tomcat EncryptInterceptor 绕过漏洞复现(使用GLM5.1复现完成)

★ 12 · 2026-04-15
404-src/CVE-2026-34486

Apache Tomcat EncryptInterceptor Bypass → Unauthenticated RCE (CVE-2026-34486)

★ 9 · 2026-04-15
razureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction

★ 0 · 2026-07-23
CypherHippie/CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

★ 0 · 2026-08-19
CVE-2024-1086
HOTMULTI PoC
PoCs 17 ★ 2459 Last push 2026-08-18 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 8 of 17 repositories
Notselwyn/CVE-2024-1086

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu…

★ 2459 · 2024-04-17
LLfam/CVE-2024-1086
★ 22 · 2024-12-16
kevcooper/CVE-2024-1086-checker
★ 2 · 2024-06-10
sandesh9978/cve-2024-1086-lpe

Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Include…

★ 1 · 2026-03-07
dopaminauta/onetwoseven-writeup

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

★ 1 · 2026-08-06
CCIEVoice2009/CVE-2024-1086
★ 0 · 2024-04-30
feely666/CVE-2024-1086
★ 0 · 2024-06-10
< Prev Page 13 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.