Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
349PoC updated in 7 days
filters
803 results
PoCs 5
★ 3
Last push 2026-08-28 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
PoCs 7
★ 113
Last push 2026-08-27 (1 month, 1 week ago)
Fetching description from NVD…
Show 7 repositories
bjrjk/CVE-2025-43529
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
★ 18 · 2026-02-01
SimoesCTT/CTT-Apple-Silicon-Refraction
webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the …
★ 1 · 2026-01-30
PoCs 5
★ 71
Last push 2026-08-27 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
Jasmoon99/Embedded-PDF
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedd…
★ 71 · 2021-06-06
omarothmann/Embedded-Backdoor-Connection
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedde…
★ 8 · 2022-01-26
ocfagb/hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-12…
★ 0 · 2026-08-27
PoCs 6
★ 152
Last push 2026-08-27 (1 month, 1 week ago)
Fetching description from NVD…
Show 6 repositories
synacktiv/Livepyre
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
★ 152 · 2026-07-16
HelgeSverre/livewire-honeypot
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068, and CVE-20…
★ 6 · 2026-05-15
e4zyy/Project-CVE-2025-54068
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
★ 4 · 2026-08-27
PoCs 5
★ 11
Last push 2026-08-27 (1 month, 1 week ago)
Fetching description from NVD…
Show 5 repositories
renzi25031469/CVE-2026-19478
Nuclei detection template for CVE-2026-19478, a critical (CVSS 9.4) unauthenticated arbitrary method invocation flaw in the GitLab GraphQL API,
★ 1 · 2026-08-19
PoCs 7
★ 7
Last push 2026-08-26 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
plur1bu5/CVE-2025-2945-pgadmin-rce
Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes
★ 0 · 2026-03-16
g0d150ne/CVE-2025-2945
Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.
★ 0 · 2026-08-10
PoCs 13
★ 4
Last push 2026-08-25 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
BridgerAlderson/CVE-2025-69212-PoC
OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.
★ 4 · 2026-07-02
m2sousa/CVE-2025-69212
CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.
★ 0 · 2026-07-01
PoCs 24
★ 27
Last push 2026-08-25 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 24 repositories
kxisxr/Bash-Script-CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Executio…
★ 2 · 2021-11-30
PoCs 9
★ 108
Last push 2026-08-25 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
0xhaggis/CVE-2022-42475
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
★ 33 · 2023-06-21
uLl0a/cve-2022-42475-poc
Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the S…
★ 1 · 2026-08-25
PoCs 5
★ 43
Last push 2026-08-24 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
WismanSec/sharepoint-2026-poc
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE,…
★ 2 · 2026-08-06
ChPratik/CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
★ 0 · 2026-07-27
PoCs 122
★ 1185
Last push 2026-08-24 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 122 repositories
Cyb0r9/ispy
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
★ 245 · 2021-02-06
PoCs 26
★ 248
Last push 2026-08-24 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 26 repositories
ndrscodes/http2-rst-stream-attacker
Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's…
★ 6 · 2024-01-11
PoCs 13
★ 131
Last push 2026-08-23 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
Cythonic1/CVE-2024-9264
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
★ 3 · 2025-06-05
PoCs 7
★ 23
Last push 2026-08-22 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
JohnDoeAnonITA/CVE-2024-28000
CVE-2024-28000 Exploit for litespeed-cache =<6.3 allows Privilege Escalation with creation of administrator account
★ 5 · 2025-03-18
AliHzSec/CVE-2024-28000
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environm…
★ 0 · 2026-07-30
PoCs 14
★ 389
Last push 2026-08-22 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
tamim1089/HikvisionExploiter
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the W…
★ 389 · 2025-12-22
Aiminsun/CVE-2021-36260
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability t…
★ 305 · 2021-10-28
sylhetyhackvenger/HIKRAVEN
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests de…
★ 7 · 2026-08-22
PoCs 8
★ 24
Last push 2026-08-22 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 repositories
ExDev994/CVE-2026-0740-mass
PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.
★ 1 · 2026-07-11
PoCs 7
★ 19
Last push 2026-08-21 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
dinosn/ghost-cve-2026-26980
CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)
★ 19 · 2026-04-18
PoCs 5
★ 27
Last push 2026-08-21 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
M3str3/CVE-2026-2005
PoC for CVE-2026-2005 — heap buffer overflow in PostgreSQL pgcrypto (pgp_pub_decrypt). Oversized PGP session key bypasses bounds check in pgp-pubdec.c. Affects…
★ 0 · 2026-03-07
PoCs 7
★ 10
Last push 2026-08-21 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 19
★ 35
Last push 2026-08-21 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
walnutsecurity/cve-2022-36804
A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects a…
★ 8 · 2023-01-25
PoCs 12
★ 6
Last push 2026-08-20 (1 month, 2 weeks ago)
Fetching description from NVD…
Show 8 of 12 repositories
zycoder0day/CVE-2026-8181
CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept
★ 6 · 2026-05-15
murrez/CVE-2026-8181
CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports. Authorized…
★ 4 · 2026-05-15
Jenderal92/CVE-2026-8181
CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.
★ 0 · 2026-05-30
x48ps/CVE-2026-8181
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any inc…
★ 0 · 2026-05-22
Yucaerin/CVE-2026-8181
The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass
★ 0 · 2026-05-22
PoCs 6
★ 1
Last push 2026-08-19 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
AetherAI3/AETHER-PROTOCOL-P
Working implementation: cryptographically verified short-lived identities for AI decision authentication — CVE-2025-59536 (Patent Pending US 64/006,746)
★ 1 · 2026-08-19
TreRB/ai-ide-config-guard
Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CV…
★ 0 · 2026-04-20
Perufitlife/dotclaude-security
Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-2185…
★ 0 · 2026-06-21
PoCs 45
★ 22
Last push 2026-08-19 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 8 of 45 repositories
gunzf0x/CVE-2025-24893
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
★ 22 · 2025-08-22
Infinit3i/CVE-2025-24893
PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered asynchronously. It a…
★ 6 · 2025-09-02
Hex00-0x4/CVE-2025-24893-XWiki-RCE
This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine SolrSearch
★ 6 · 2025-08-08
PoCs 5
★ 69
Last push 2026-08-19 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
striga-ai/CVE-2026-34486
EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.
★ 69 · 2026-05-11
PoCs 17
★ 2459
Last push 2026-08-18 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 8 of 17 repositories
Notselwyn/CVE-2024-1086
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu…
★ 2459 · 2024-04-17
sandesh9978/cve-2024-1086-lpe
Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Include…
★ 1 · 2026-03-07
dopaminauta/onetwoseven-writeup
HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root
★ 1 · 2026-08-06
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.