Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2015-1805
HOTMULTI PoC
PoCs 6 ★ 276 Last push 2026-08-18 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 6 repositories
dosomder/iovyroot

CVE-2015-1805 root tool

★ 276 · 2017-11-23
panyu6325/CVE-2015-1805
★ 31 · 2016-04-20
ireshchaminda1/Android-Privilege-Escalation-Remote-Access-Vulnerability-CVE-2015-1805

AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT is designe…

★ 6 · 2023-02-12
FloatingGuy/cve-2015-1805
★ 3 · 2016-06-30
valentineus/hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

★ 1 · 2026-08-18
mobilelinux/iovy_root_research

A root tool based on the [CVE-2015-1805 vulnerability](https://access.redhat.com/security/cve/cve-2015-1805) It supports 32 and 64bit, get sys call table addr…

★ 0 · 2018-11-01
CVE-2017-9248
HOTMULTI PoC
PoCs 7 ★ 178 Last push 2026-08-17 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 7 repositories
bao7uo/dp_crypto

Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)

★ 178 · 2020-12-22
capt-meelo/Telewreck

A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.

★ 96 · 2018-08-14
blacklanternsecurity/dp_cryptomg

Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.

★ 61 · 2026-08-17
0xsharz/telerik-scanner-cve-2017-9248

Telerik CVE-2017-9248 Vulnerability Scanner

★ 2 · 2025-08-22
ictnamanh/CVE-2017-9248
★ 0 · 2019-10-23
oldboysonnt/dp

Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX

★ 0 · 2020-01-21
cehamod/UI_CVE-2017-9248

Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)

★ 0 · 2023-06-05
CVE-2021-42574
MULTI PoC
PoCs 9 ★ 8 Last push 2026-08-16 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 8 of 9 repositories
simplylu/CVE-2021-42574

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

★ 8 · 2023-05-23
maweil/bidi_char_detector

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

★ 6 · 2023-03-28
Moshe-ship/bidi-guard

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

★ 5 · 2026-04-04
rakib-nyc/nullorigin

Research-only AI watermark & provenance robustness toolkit: local reverse proxy (OpenAI/Anthropic/Gemini) + CLI stripping C2PA/EXIF/XMP, zero-width & homoglyph…

★ 4 · 2026-08-16
tin-z/solidity_CVE-2021-42574-POC

POC of CVE-2021-42574 for solidity and solc compiler

★ 3 · 2023-02-01
sotiak/CVE-2021-42574
★ 1 · 2021-11-01
waseeld/CVE-2021-42574
★ 1 · 2021-12-11
CVE-2022-1471
MULTI PoC
PoCs 7 ★ 8 Last push 2026-08-15 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 7 repositories
1fabunicorn/SnakeYAML-CVE-2022-1471-POC

Code for veracode blog

★ 8 · 2023-03-02
falconkei/snakeyaml_cve_poc

SnakeYAML-CVE-2022-1471-POC

★ 4 · 2023-12-24
seal-sec-demo-2/yaml-payload

SnakeYAML CVE-2022-1471 exploit payload for demo

★ 0 · 2026-02-13
jelee2555/CVE-2022-1471-attacker

attacker

★ 0 · 2026-03-11
anupamojha-eng/sentinel-transitive-cve-demo

Sentinel demo: transitive snakeyaml CVE-2022-1471 via Spring Boot + exploitable code pattern

★ 0 · 2026-06-02
seal-sec-demo-2/yaml-payload-2

SnakeYAML CVE-2022-1471 exploit payload for Seal Security demos

★ 0 · 2026-07-17
aykhan019/cve-2022-1471-jira-lab
★ 0 · 2026-08-15
CVE-2019-1040
HOTMULTI PoC
PoCs 6 ★ 300 Last push 2026-08-15 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 6 repositories
fox-it/cve-2019-1040-scanner
★ 300 · 2020-11-09
Ridter/CVE-2019-1040

CVE-2019-1040 with Exchange

★ 249 · 2021-06-18
QAX-A-Team/dcpwn

an impacket-dependent script exploiting CVE-2019-1040

★ 73 · 2021-01-01
Ridter/CVE-2019-1040-dcpwn

CVE-2019-1040 with Kerberos delegation

★ 33 · 2021-06-18
lazaars/UltraRealy_with_CVE-2019-1040

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

★ 19 · 2019-06-19
JonyFilc/PrintSpoofer-ReflectiveDLL

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration testing.

★ 2 · 2026-08-15
CVE-2021-36934
HOTMULTI PoC
PoCs 24 ★ 208 Last push 2026-08-15 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 8 of 24 repositories
HuskyHacks/ShadowSteal

Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation

★ 208 · 2022-01-16
WiredPulse/Invoke-HiveNightmare

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer

★ 35 · 2022-09-24
JoranSlingerland/CVE-2021-36934

Fix for the CVE-2021-36934

★ 9 · 2021-10-15
romarroca/SeriousSam

HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934

★ 9 · 2021-07-22
Wh04m1001/VSSCopy

Small and dirty PoC for CVE-2021-36934

★ 8 · 2021-07-22
Sp00kySkelet0n/PyNightmare

PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3

★ 7 · 2021-07-25
exploitblizzard/CVE-2021-36934

HiveNightmare aka SeriousSAM

★ 7 · 2021-07-27
n3tsurge/CVE-2021-36934

Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)

★ 5 · 2021-07-22
CVE-2023-32784
HOTMULTI PoC
PoCs 14 ★ 651 Last push 2026-08-14 (1 month, 3 weeks ago)

Fetching description from NVD…

Show 8 of 14 repositories
vdohney/keepass-password-dumper

Original PoC for CVE-2023-32784

★ 651 · 2023-08-17
z-jxy/keepass_dump

KeePass 2.X dumper (CVE-2023-32784)

★ 29 · 2023-11-04
und3sc0n0c1d0/BruteForce-to-KeePass

This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting KeePass.

★ 6 · 2023-05-21
mister-turtle/cve-2023-32784
★ 4 · 2024-02-01
CTM1/CVE-2023-32784-keepass-linux

KeePass Master Password Extraction PoC for Linux

★ 2 · 2024-01-27
hau-zy/KeePass-dump-py

Re-write of original KeePass 2.X Master Password Dumper (CVE-2023-32784) POC in python.

★ 0 · 2023-06-04
dawnl3ss/CVE-2023-32784

Retrieve the master password of a keepass database <= 2.53.1

★ 0 · 2023-08-30
Cmadhushanka/CVE-2023-32784-Exploitation

year 2 semester 1 Systems and Network Programming Assignment

★ 0 · 2024-07-10
CVE-2016-6662
MULTI PoC
PoCs 6 ★ 28 Last push 2026-08-12 (1 month, 4 weeks ago)

Fetching description from NVD…

Show 6 repositories
MAYASEVEN/CVE-2016-6662

From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN

★ 28 · 2017-07-22
Ashrafdev/MySQL-Remote-Root-Code-Execution

0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.

★ 9 · 2026-08-12
meersjo/ansible-mysql-cve-2016-6662

Simple ansible playbook to patch mysql servers against CVE-2016-6662

★ 1 · 2016-09-19
boompig/cve-2016-6662
★ 1 · 2017-03-20
konstantin-kelemen/mysqld_safe-CVE-2016-6662-patch

MySQL server CVE-2016-6662 patch playbook

★ 0 · 2016-09-15
KosukeShimofuji/CVE-2016-6662

research CVE-2016-6662

★ 0 · 2016-09-16
CVE-2022-35914
MULTI PoC
PoCs 9 ★ 52 Last push 2026-08-11 (1 month, 4 weeks ago)

Fetching description from NVD…

Show 8 of 9 repositories
cosad3s/CVE-2022-35914-poc
★ 52 · 2024-01-02
senderend/CVE-2022-35914

PoC exploit for GLPI - Command injection using a third-party library script

★ 4 · 2024-10-17
Lzer0Kx01/CVE-2022-35914
★ 2 · 2022-10-09
0xGabe/CVE-2022-35914

Unauthenticated RCE in GLPI 10.0.2

★ 2 · 2022-11-06
noxlumens/CVE-2022-35914_poc

Modified for GLPI Offsec Lab: call_user_func, array_map, passthru

★ 2 · 2024-08-25
6E6L6F/CVE-2022-35914
★ 1 · 2022-10-12
Johnermac/CVE-2022-35914

Script in Ruby for the CVE-2022-35914 - RCE in GLPI

★ 0 · 2023-03-07
btar1gan/exploit_CVE-2022-35914
★ 0 · 2024-09-20
CVE-2025-64459
MULTI PoC
PoCs 10 ★ 2 Last push 2026-08-11 (1 month, 4 weeks ago)

Fetching description from NVD…

Show 8 of 10 repositories
omarkurt/django-connector-CVE-2025-64459-testbed

A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.

★ 2 · 2025-11-21
0xCyberstan/CVE-2025-64459-Poc

Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.…

★ 2 · 2025-12-01
nunpa/CVE-2025-64459

check if vulnerable python-django version to CVE-2025-64459 bug

★ 1 · 2025-11-13
Z3YR0xX/CVE-2025-64459
★ 0 · 2025-12-05
purehate/CVE-2025-64459-hunter

CVE-2025-64459-hunter

★ 0 · 2026-02-15
joshualent/django-cve-2025-64459

demo application showing off SQL Injection exploit in django 5.2.7

★ 0 · 2026-06-23
CVE-2023-21839
HOTMULTI PoC
PoCs 8 ★ 240 Last push 2026-08-11 (1 month, 4 weeks ago)

Fetching description from NVD…

Show 8 repositories
DXask88MA/Weblogic-CVE-2023-21839
★ 240 · 2023-02-26
ASkyeye/CVE-2023-21839

Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)

★ 116 · 2026-08-11
dinosn/CVE-2024-20931

CVE-2024-20931, this is the bypass of the patch of CVE-2023-21839

★ 61 · 2024-02-06
Firebasky/CVE-2023-21839

CVE-2023-21839工具

★ 26 · 2023-03-11
houqe/POC_CVE-2023-21839

CVE-2023-21839 Python版本

★ 19 · 2023-04-21
dinosn/CVE-2024-21182

Reproducible Docker lab for CVE-2024-21182 — Oracle WebLogic T3/IIOP OpaqueReference JNDI injection → unauthenticated RCE (CVE-2023-21839 patch-bypass family).…

★ 3 · 2026-06-02
Romanc9/Gui-poc-test

A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432

★ 2 · 2023-12-05
CVE-2026-48710
MULTI PoC
PoCs 5 ★ 3 Last push 2026-08-11 (1 month, 4 weeks ago)

Fetching description from NVD…

Show 5 repositories
eris-ths/supply-chain-guard

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT …

★ 3 · 2026-07-02
xtremebeing/starlette-host-header-lab

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

★ 1 · 2026-05-27
Bhanunamikaze/BadHost-CVE-2026-48710-Exploit

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

★ 1 · 2026-05-29
sb-ox/repro-OXDEV-77637-uv-workspace

OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyprojec…

★ 0 · 2026-08-03
CuteeCat/CVE-2026-48710

CVE-2026-48710漏洞验证代码

★ 0 · 2026-08-11
CVE-2023-0386
HOTMULTI PoC
PoCs 19 ★ 417 Last push 2026-08-10 (2 months ago)

Fetching description from NVD…

Show 8 of 19 repositories
xkaneiki/CVE-2023-0386

CVE-2023-0386在ubuntu22.04上的提权

★ 417 · 2023-06-13
chenaotian/CVE-2023-0386

CVE-2023-0386 analysis and Exp

★ 123 · 2023-05-06
sxlmnwb/CVE-2023-0386

Vulnerabilities Exploitation On Ubuntu 22.04

★ 56 · 2023-05-16
puckiestyle/CVE-2023-0386
★ 22 · 2023-12-23
Fanxiaoyao66/CVE-2023-0386

非常简单的CVE-2023-0386's exp and analysis.Use c and sh.

★ 21 · 2023-06-28
veritas501/CVE-2023-0386
★ 10 · 2023-04-20
P4x1s/CVE-2023-0386

CVE-2023-0386 EXP

★ 4 · 2023-05-08
CVE-2023-50164
MULTI PoC
PoCs 15 ★ 84 Last push 2026-08-10 (2 months ago)

Fetching description from NVD…

Show 8 of 15 repositories
jakabakos/CVE-2023-50164-Apache-Struts-RCE

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload parameters …

★ 84 · 2025-11-03
dwisiswant0/cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

★ 57 · 2023-12-18
Trackflaw/CVE-2023-50164-ApacheStruts2-Docker

Vulnerable docker container for Apache Struts 2 RCE CVE-2023-50164

★ 7 · 2023-12-20
snyk-labs/CVE-2023-50164-POC
★ 6 · 2025-12-04
bcdannyboy/CVE-2023-50164

A scanning utility and PoC for CVE-2023-50164

★ 4 · 2023-12-15
Trackflaw/CVE-2024-10924-Wordpress-Docker

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

★ 3 · 2024-11-22
sunnyvale-it/CVE-2023-50164-PoC

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

★ 2 · 2024-01-16
helsecert/cve-2023-50164
★ 1 · 2023-12-18
CVE-2023-30258
MULTI PoC
PoCs 11 ★ 14 Last push 2026-08-10 (2 months ago)

Fetching description from NVD…

Show 8 of 11 repositories
AdityaBhatt3010/Room-Walkthrough-Billing

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

★ 14 · 2026-07-13
Chocapikk/CVE-2023-30258

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

★ 2 · 2025-03-16
n00o00b/CVE-2023-30258-RCE-POC

POC for CVE-2023-30258-RCE by n0o0b

★ 1 · 2025-03-25
estebanzarate/CVE-2023-30258-Magnus-Billing-v7-Command-Injection-PoC

Unauthenticated command injection vulnerability in Magnus Billing v7.3.0.

★ 1 · 2026-02-25
gy741/CVE-2023-30258-setup
★ 0 · 2024-01-27
sk00l/CVE-2023-30258
★ 0 · 2025-04-20
abdullohqurbon0v/CVE-2023-30258-Exploit-For-Magnus-Billing-System

There are Exploit for Magnus Billing v7 system get root privilages

★ 0 · 2025-09-18
CVE-2017-14980
MULTI PoC
PoCs 9 ★ 2 Last push 2026-08-10 (2 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
TheMalwareGuardian/CVE-2017-14980

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can corrupt stack …

★ 1 · 2026-03-23
godoy-sec/CVE-2017-14980

Study of a classic stack-based buffer overflow vulnerability in a controlled lab environment for educational purposes.

★ 1 · 2026-08-10
TheDarthMole/CVE-2017-14980
★ 0 · 2023-02-03
xn0kkx/Exploit_Sync_Breeze_v10.0.28_CVE-2017-14980

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

★ 0 · 2025-02-08
DaviGSantana/CVE-2017-14980

STACK BUFFER OVERFLOW EXPLOIT RESULTING IN REMOTE CODE EXECUTION

★ 0 · 2026-01-20
damariion/CVE-2017-14980.RCE

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login

★ 0 · 2026-03-02
0xkr3pt0n/CVE-2017-14980

CVE-2017-14980 python exploit

★ 0 · 2026-05-09
CVE-2023-32233
HOTMULTI PoC
PoCs 8 ★ 380 Last push 2026-08-09 (2 months ago)

Fetching description from NVD…

Show 8 repositories
Liuk3r/CVE-2023-32233

CVE-2023-32233: Linux内核中的安全漏洞

★ 380 · 2023-05-16
oferchen/POC-CVE-2023-32233

Use-After-Free in Netfilter nf_tables when processing batch requests CVE-2023-32233

★ 53 · 2023-06-20
PIDAN-HEIDASHUAI/CVE-2023-32233

自用,poc作者为Piotr Krysiuk,在使用前请先阅读README.md

★ 3 · 2023-05-16
void0red/CVE-2023-32233
★ 1 · 2024-04-01
Destawell/gemini-2.5-pro-nf-tables-red-teaming

Gemini 2.5 Pro nf_tables Red Teaming Case Study (CVE-2023-32233) — LLM Safety Alignment & Responsible Disclosure

★ 1 · 2026-07-15
RogelioPumajulca/TEST-CVE-2023-32233

CVE-2023-32233

★ 0 · 2024-02-04
Destawell/gemini-2.5-pro-nf-tables-red-teamin

A technical case study and timeline dataset documenting Google Gemini 2.5 Pro's safety alignment policies, guardrails, and refusal behavior evolution regarding…

★ 0 · 2026-05-31
adeadukagi/CVE-2023-32233-reproduction

A Linux-related vulnerability

★ 0 · 2026-08-09
CVE-2017-8464
MULTI PoC
PoCs 9 ★ 67 Last push 2026-08-09 (2 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
3gstudent/CVE-2017-8464-EXP

Support x86 and x64

★ 67 · 2021-04-17
doudouhala/CVE-2017-8464-exp-generator

this tool can generate a exp for cve-2017-8486, it is developed by python

★ 8 · 2017-08-07
TrG-1999/DetectPacket-CVE-2017-8464

Exploit vulnerabilities and vulnerability prevention implementation

★ 3 · 2022-06-08
Elm0D/CVE-2017-8464
★ 1 · 2017-09-20
xssfile/CVE-2017-8464-EXP
★ 1 · 2018-04-20
X-Vector/usbhijacking

Usbhijacking | CVE-2017-8464

★ 0 · 2018-07-20
TieuLong21Prosper/Detect-CVE-2017-8464

- using python to detect cve-2017-8464 vulnerbilities

★ 0 · 2023-11-27
CVE-2019-14287
MULTI PoC
PoCs 27 ★ 13 Last push 2026-08-08 (2 months ago)

Fetching description from NVD…

Show 8 of 27 repositories
n0w4n/CVE-2019-14287

Sudo exploit

★ 13 · 2019-10-15
CMNatic/Dockerized-CVE-2019-14287

Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.

★ 7 · 2020-02-09
shallvhack/Sudo-Security-Bypass-CVE-2019-14287

Sudo Security Bypass (CVE-2019-14287)

★ 3 · 2020-07-23
FauxFaux/sudo-cve-2019-14287
★ 1 · 2019-10-15
CashWilliams/CVE-2019-14287-demo

This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287

★ 1 · 2020-11-16
MariliaMeira/CVE-2019-14287
★ 1 · 2022-10-12
gurneesh/CVE-2019-14287-write-up
★ 0 · 2019-10-16
huang919/cve-2019-14287-PPT
★ 0 · 2019-11-13
CVE-2023-6553
MULTI PoC
PoCs 7 ★ 87 Last push 2026-08-08 (2 months ago)

Fetching description from NVD…

Show 7 repositories
Chocapikk/CVE-2023-6553

Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution

★ 87 · 2024-02-06
motikan2010/CVE-2023-6553-PoC
★ 4 · 2023-12-27
0x00phantom-hat/CVE-2023-6553-RCE-Exploit

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php…

★ 2 · 2026-04-10
cc3305/CVE-2023-6553

CVE-2023-6553 exploit script

★ 0 · 2024-07-27
Harshit-Mashru/CVE-2023-6553

Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress

★ 0 · 2024-11-07
joaoaugustom/WordPress_Backup_Migration-RCE_Unauthenticated

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

★ 0 · 2026-08-08
Dungsocool/CVE-2023-6553
★ 0 · 2026-08-05
CVE-2026-42208
MULTI PoC
PoCs 6 ★ 1 Last push 2026-08-07 (2 months ago)

Fetching description from NVD…

Show 6 repositories
ridhinva/litellm-sqli-scanner

Scanner: CVE-2026-42208 LiteLLM SQL Injection — Python scanner for BerriAI LiteLLM proxy instances

★ 1 · 2026-08-07
imjdl/CVE-2026-42208_lab

CVE-2026-42208 lab

★ 0 · 2026-04-28
0xBlackash/CVE-2026-42208

CVE-2026-40487

★ 0 · 2026-05-04
Zeltoc/threat-intel-brief-cve-2026-42208-litellm

Threat intelligence brief on CVE-2026-42208, a critical pre-auth SQL injection in BerriAI LiteLLM exploited within 36 hours of disclosure. Covers attack path, …

★ 0 · 2026-05-10
HAERIN-L/poc_cve-2026-42208
★ 0 · 2026-05-30
CVE-2026-9082
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-89 Published 2026-05-20 PoCs 12 ★ 23 Last push 2026-08-07 (2 months ago)

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection. This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.

Show 8 of 12 repositories
7h30th3r0n3/CVE-2026-9082-Drupal-PoC

Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module…

★ 23 · 2026-05-21
N45HT/drupal-cve-2026-9082-checker

Drupal CVE-2026-9082 Blind SQL Injection Checker

★ 8 · 2026-05-24
HORKimhab/CVE-2026-9082

CVE-2026-9082 | SA-CORE-2026-004

★ 2 · 2026-05-21
ridhinva/drupal-jsonapi-sqli-scanner

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

★ 2 · 2026-08-07
0xBlackash/CVE-2026-9082

CVE-2026-9082

★ 1 · 2026-06-04
ywh-jfellus/CVE-2026-9082

PoC for CVE-2026-9082 (Drupal SA-CORE-2026-004) Drupal Core SQLi

★ 1 · 2026-05-21
sourcecode347/CVE-2026-9082-Mass_Scanner

Mass Scanner For Drupal Exploit CVE-2026-9082

★ 1 · 2026-06-16
CVE-2026-1731
MULTI PoC
PoCs 5 ★ 37 Last push 2026-08-07 (2 months ago)

Fetching description from NVD…

Show 5 repositories
win3zz/CVE-2026-1731

CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash arithmetic evaluation in…

★ 37 · 2026-02-11
jakubie07/CVE-2026-1731

CVE-2026-1731 PoC

★ 6 · 2026-05-02
cybrdude/cve-2026-1731-scanner

Passive vulnerability scanner for CVE-2026-1731 — BeyondTrust RS/PRA pre-auth RCE (CVSS 9.9). Educational & defensive use only.

★ 4 · 2026-02-16
hex0user/CVE-2026-1731

CVE-2026-1731 — BeyondTrust Remote Code Execution Vulnerability

★ 1 · 2026-02-22
ridhinva/beyondtrust-rce-scanner

Scanner: CVE-2026-1731 BeyondTrust Remote Support Pre-auth RCE — Python checker for actively exploited vulnerability (CISA KEV)

★ 0 · 2026-08-07
CVE-2026-0300
MULTI PoC
PoCs 10 ★ 22 Last push 2026-08-07 (2 months ago)

Fetching description from NVD…

Show 8 of 10 repositories
p3Nt3st3r-sTAr/CVE-2026-0300-POC
★ 22 · 2026-05-07
matad0r-maghribi/CVE-2026-0300-PANOS

Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.

★ 4 · 2026-05-06
qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC

A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™ Authentication Por…

★ 3 · 2026-05-06
ridhinva/panos-captive-portal-rce

Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls…

★ 2 · 2026-08-07
mr-r3b00t/CVE-2026-0300

a honeypot for CVE-2026-0300

★ 1 · 2026-05-06
shizuku198411/CVE-2026-0300

PAN-OS CVE-2026-0300 Non-Destructive Exposure Survey Tool

★ 1 · 2026-05-06
0xBlackash/CVE-2026-0300

CVE-2026-0300

★ 1 · 2026-05-06
TailwindRG/cve-2026-0300-audit

Read-only audit tooling for CVE-2026-0300 (PAN-OS User-ID Authentication Portal exposure)

★ 0 · 2026-05-06
CVE-2025-68645
MULTI PoC
PoCs 7 ★ 3 Last push 2026-08-07 (2 months ago)

Fetching description from NVD…

Show 7 repositories
MaxMnMl/zimbramail-CVE-2025-68645-poc

CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration

★ 3 · 2026-01-04
codeb0ssx/CVE-2025-68645-PoC

Academic proof-of-concept demonstrating CVE-2025-68645 for authorized security research.

★ 2 · 2025-12-30
0xBlackash/CVE-2025-68645

CVE-2025-68645

★ 2 · 2026-04-24
HarisAidhin/Poc_CVE-2025-68645

Zimbra Path Traversal (CVE-2025-68645) - Unauthenticated file read vulnerability in Zimbra Collaboration Suite

★ 1 · 2026-05-06
Crow5-oss/CVE-2025-68645
★ 0 · 2026-02-21
Ashwesker/Ashwesker-CVE-2025-68645

POC BLH Magelang CSIRT 2026 by babyrootkid

★ 0 · 2026-08-07
< Prev Page 14 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.