Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 96
★ 526
Last push 2026-08-06 (2 months ago)
Fetching description from NVD…
Show 8 of 96 repositories
xaitax/CVE-2024-6387_Check
CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH
★ 526 · 2026-05-29
l0n3m4n/CVE-2024-6387
PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)
★ 114 · 2024-07-05
xonoxitron/regreSSHion
CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.
★ 71 · 2024-07-02
PoCs 5
★ 5
Last push 2026-08-06 (2 months ago)
Fetching description from NVD…
Show 5 repositories
tc4dy/CVE-2026-61511-PoC-Exploit
CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full toolkit: reverse …
★ 5 · 2026-08-06
codeb0ssx/Ultimate-CVE-2026-61511
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template r…
★ 0 · 2026-07-29
PoCs 44
★ 314
Last push 2026-08-04 (2 months ago)
Fetching description from NVD…
Show 8 of 44 repositories
exfil0/CVE-2025-53770
A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE) vulnerability in…
★ 5 · 2025-07-23
PoCs 5
★ 44
Last push 2026-08-03 (2 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
R3fr4kt/Codify-TJNULL-OSCP-
Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege Escalation via B…
★ 0 · 2026-08-03
PoCs 5
★ 243
Last push 2026-08-03 (2 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
d0rb/CVE-2023-36874
This repository contains a proof-of-concept exploit written in C++ that demonstrates the exploitation of a vulnerability affecting the Windows Error Reporting …
★ 79 · 2024-03-13
johnnygreeme/CVE-2023-36874
Educational Proof of Concept (PoC) for CVE-2023-36874 — Windows Error Reporting (WER) Local Privilege Escalation vulnerability.
★ 0 · 2026-08-03
PoCs 16
★ 360
Last push 2026-08-03 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 16 repositories
mauricelambert/CVE-2022-21907
CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: P…
★ 26 · 2022-03-07
PoCs 7
★ 30
Last push 2026-08-02 (2 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
jeffaf/cve-2026-32746
CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8)
★ 30 · 2026-03-20
MonkeySeC-sys/Kangaroo
Kangaroo is a exploit built on CVE-2026-32746. i made this for security researchers, IT professionals, DevOps. so they can understand it better. DO NOT USE TH…
★ 2 · 2026-08-02
PoCs 27
★ 1484
Last push 2026-08-02 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 27 repositories
Schira4396/VcenterKiller
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密…
★ 1484 · 2024-04-25
psc4re/NSE-scripts
NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
★ 162 · 2021-08-16
PoCs 26
★ 559
Last push 2026-08-01 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 26 repositories
wmasday/HTC
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
★ 3 · 2023-07-27
PoCs 55
★ 47
Last push 2026-08-01 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 55 repositories
un9nplayer/CVE-2024-24919
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The vulnerability allows …
★ 16 · 2024-06-05
PoCs 6
★ 4
Last push 2026-07-31 (2 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
GarlicB/jquery35-local-agent
Offline jQuery CVE-2020-11023 remediation kit for legacy Spring/JSP - Node.js built-ins only (no npm, no internet)
★ 1 · 2026-07-31
PoCs 51
★ 247
Last push 2026-07-31 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 51 repositories
Flangvik/SharpProxyLogon
C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection
★ 247 · 2021-03-31
hosch3n/ProxyVulns
[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains. [ProxyShell] CVE-2021…
★ 175 · 2022-10-21
dwisiswant0/proxylogscan
A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (…
★ 166 · 2022-03-02
cert-lv/exchange_webshell_detection
Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, …
★ 98 · 2021-03-16
PoCs 15
★ 91
Last push 2026-07-31 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 15
★ 209
Last push 2026-07-31 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 15 repositories
corelight/CVE-2020-16898
A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)
★ 9 · 2024-09-03
PoCs 15
★ 280
Last push 2026-07-31 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 15 repositories
ZephrFish/CVE-2020-1350_HoneyPoC
HoneyPoC: Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server 2000 up to Window…
★ 280 · 2026-07-31
psc4re/NSE-scripts
NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473
★ 162 · 2021-08-16
T13nn3s/CVE-2020-1350
This Powershell Script is checking if your server is vulnerable for the CVE-2020-1350 Remote Code Execution flaw in the Windows DNS Service
★ 15 · 2023-04-01
corelight/SIGRed
Detection of attempts to exploit Microsoft Windows DNS server via CVE-2020-1350 (AKA SIGRed)
★ 9 · 2020-07-20
PoCs 13
★ 33
Last push 2026-07-30 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 13 repositories
verylazytech/CVE-2025-64446
CVE-2025-64446 - A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, …
★ 3 · 2025-11-19
PoCs 64
★ 229
Last push 2026-07-30 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 64 repositories
PoCs 44
★ 162
Last push 2026-07-30 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 44 repositories
PoCs 31
★ 151
Last push 2026-07-29 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 31 repositories
PoCs 18
★ 54
Last push 2026-07-28 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 18 repositories
0xcan1337/CVE-2025-47812-poC
Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.
★ 13 · 2025-07-01
PoCs 11
★ 70
Last push 2026-07-28 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 11 repositories
JustThinkingHard/HID-Attack
Full BadUSB attack chain: keystroke-injection payload delivery, C2 client, privilege escalation (CVE-2025-6019), and systemd persistence on Linux.
★ 0 · 2025-07-08
PoCs 10
★ 117
Last push 2026-07-28 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
dinosn/liferay-ga4-rce-research
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agen…
★ 7 · 2026-07-28
PoCs 8
★ 101
Last push 2026-07-27 (2 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
PoCs 11
★ 10
Last push 2026-07-24 (2 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 11 repositories
saqibnet/blackbox-pentesting-infsecos
Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation
★ 0 · 2026-05-08
PoCs 17
★ 407
Last push 2026-07-24 (2 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 17 repositories
GeneralTesler/CVE-2016-10033
RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html
★ 9 · 2017-05-10
Zenexer/safeshell
Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.
★ 8 · 2016-12-29
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.