Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 6
★ 276
Last push 2026-08-18 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
mobilelinux/iovy_root_research
A root tool based on the [CVE-2015-1805 vulnerability](https://access.redhat.com/security/cve/cve-2015-1805) It supports 32 and 64bit, get sys call table addr…
★ 0 · 2018-11-01
PoCs 7
★ 178
Last push 2026-08-17 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
bao7uo/dp_crypto
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
★ 178 · 2020-12-22
capt-meelo/Telewreck
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
★ 96 · 2018-08-14
oldboysonnt/dp
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
★ 0 · 2020-01-21
cehamod/UI_CVE-2017-9248
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
★ 0 · 2023-06-05
PoCs 9
★ 8
Last push 2026-08-16 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
maweil/bidi_char_detector
Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574
★ 6 · 2023-03-28
Moshe-ship/bidi-guard
Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)
★ 5 · 2026-04-04
rakib-nyc/nullorigin
Research-only AI watermark & provenance robustness toolkit: local reverse proxy (OpenAI/Anthropic/Gemini) + CLI stripping C2PA/EXIF/XMP, zero-width & homoglyph…
★ 4 · 2026-08-16
PoCs 7
★ 8
Last push 2026-08-15 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 6
★ 300
Last push 2026-08-15 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
JonyFilc/PrintSpoofer-ReflectiveDLL
The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration testing.
★ 2 · 2026-08-15
PoCs 24
★ 208
Last push 2026-08-15 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 8 of 24 repositories
HuskyHacks/ShadowSteal
Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation
★ 208 · 2022-01-16
WiredPulse/Invoke-HiveNightmare
PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer
★ 35 · 2022-09-24
romarroca/SeriousSam
HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934
★ 9 · 2021-07-22
PoCs 14
★ 651
Last push 2026-08-14 (1 month, 3 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
und3sc0n0c1d0/BruteForce-to-KeePass
This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting KeePass.
★ 6 · 2023-05-21
hau-zy/KeePass-dump-py
Re-write of original KeePass 2.X Master Password Dumper (CVE-2023-32784) POC in python.
★ 0 · 2023-06-04
PoCs 6
★ 28
Last push 2026-08-12 (1 month, 4 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 9
★ 52
Last push 2026-08-11 (1 month, 4 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 10
★ 2
Last push 2026-08-11 (1 month, 4 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
0xCyberstan/CVE-2025-64459-Poc
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.…
★ 2 · 2025-12-01
PoCs 8
★ 240
Last push 2026-08-11 (1 month, 4 weeks ago)
Fetching description from NVD…
Show 8 repositories
dinosn/CVE-2024-21182
Reproducible Docker lab for CVE-2024-21182 — Oracle WebLogic T3/IIOP OpaqueReference JNDI injection → unauthenticated RCE (CVE-2023-21839 patch-bypass family).…
★ 3 · 2026-06-02
Romanc9/Gui-poc-test
A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432
★ 2 · 2023-12-05
PoCs 5
★ 3
Last push 2026-08-11 (1 month, 4 weeks ago)
Fetching description from NVD…
Show 5 repositories
eris-ths/supply-chain-guard
Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT …
★ 3 · 2026-07-02
sb-ox/repro-OXDEV-77637-uv-workspace
OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyprojec…
★ 0 · 2026-08-03
PoCs 19
★ 417
Last push 2026-08-10 (2 months ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 15
★ 84
Last push 2026-08-10 (2 months ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 11
★ 14
Last push 2026-08-10 (2 months ago)
Fetching description from NVD…
Show 8 of 11 repositories
Chocapikk/CVE-2023-30258
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
★ 2 · 2025-03-16
PoCs 9
★ 2
Last push 2026-08-10 (2 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
TheMalwareGuardian/CVE-2017-14980
Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can corrupt stack …
★ 1 · 2026-03-23
godoy-sec/CVE-2017-14980
Study of a classic stack-based buffer overflow vulnerability in a controlled lab environment for educational purposes.
★ 1 · 2026-08-10
damariion/CVE-2017-14980.RCE
Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login
★ 0 · 2026-03-02
PoCs 8
★ 380
Last push 2026-08-09 (2 months ago)
Fetching description from NVD…
Show 8 repositories
PoCs 9
★ 67
Last push 2026-08-09 (2 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 27
★ 13
Last push 2026-08-08 (2 months ago)
Fetching description from NVD…
Show 8 of 27 repositories
CashWilliams/CVE-2019-14287-demo
This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287
★ 1 · 2020-11-16
PoCs 7
★ 87
Last push 2026-08-08 (2 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 6
★ 1
Last push 2026-08-07 (2 months ago)
Fetching description from NVD…
Show 6 repositories
CVSS 9.8 CRITICAL
CWE-89
Published 2026-05-20
PoCs 12
★ 23
Last push 2026-08-07 (2 months ago)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core allows SQL Injection.
This issue affects Drupal core: from 8.9.0 before 10.4.10, from 10.5.0 before 10.5.10, from 10.6.0 before 10.6.9, from 11.0.0 before 11.1.10, from 11.2.0 before 11.2.12, from 11.3.0 before 11.3.10.
Show 8 of 12 repositories
7h30th3r0n3/CVE-2026-9082-Drupal-PoC
Drupal Core PostgreSQL SQL Injection PoC - CVE-2026-9082. Ethical PoC for the Drupal vulnerability allowing anonymous SQL injection through the JSON:API module…
★ 23 · 2026-05-21
PoCs 5
★ 37
Last push 2026-08-07 (2 months ago)
Fetching description from NVD…
Show 5 repositories
win3zz/CVE-2026-1731
CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash arithmetic evaluation in…
★ 37 · 2026-02-11
cybrdude/cve-2026-1731-scanner
Passive vulnerability scanner for CVE-2026-1731 — BeyondTrust RS/PRA pre-auth RCE (CVSS 9.9). Educational & defensive use only.
★ 4 · 2026-02-16
ridhinva/beyondtrust-rce-scanner
Scanner: CVE-2026-1731 BeyondTrust Remote Support Pre-auth RCE — Python checker for actively exploited vulnerability (CISA KEV)
★ 0 · 2026-08-07
PoCs 10
★ 22
Last push 2026-08-07 (2 months ago)
Fetching description from NVD…
Show 8 of 10 repositories
matad0r-maghribi/CVE-2026-0300-PANOS
Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID Portal.
★ 4 · 2026-05-06
ridhinva/panos-captive-portal-rce
Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls…
★ 2 · 2026-08-07
PoCs 7
★ 3
Last push 2026-08-07 (2 months ago)
Fetching description from NVD…
Show 7 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.