Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 5
★ 11
Last push 2026-07-15 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
PoCs 18
★ 32
Last push 2026-07-15 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 18 repositories
0x00Jeff/CVE-2025-27591
self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files
★ 15 · 2026-06-28
00xCanelo/CVE-2025-27591
🔥 Local Privilege Escalation Exploit for CVE-2025-27591 | Abuses world-writable log dir in Below to gain root via /etc/passwd injection
★ 2 · 2025-07-23
PoCs 16
★ 72
Last push 2026-07-14 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 16 repositories
naclapor/CVE-2024-28397
This repository contains a python exploit code for CVE-2024-28397 intended for use on the "CodePartTwo" machine on Hack The Box (HTB).
★ 12 · 2025-09-09
PoCs 15
★ 237
Last push 2026-07-14 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
Plazmaz/CVE-2019-18634
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
★ 59 · 2020-02-19
PoCs 39
★ 52
Last push 2026-07-14 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 39 repositories
PoCs 11
★ 719
Last push 2026-07-13 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 11 repositories
uziii2208/CVE-2025-33073
Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.
★ 67 · 2025-11-14
matejsmycka/CVE-2025-33073-checker
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samb…
★ 0 · 2025-07-31
PoCs 12
★ 8
Last push 2026-07-13 (2 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 12 repositories
j4k0m/CVE-2019-5420
A vulnerability can allow an attacker to guess the automatically generated development mode secret token.
★ 5 · 2021-09-07
PoCs 15
★ 190
Last push 2026-07-12 (2 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
jaiguptanick/CVE-2019-0232
Vulnerability analysis and PoC for the Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (RCE)
★ 33 · 2021-09-04
PoCs 9
★ 29
Last push 2026-07-12 (2 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
sfewer-r7/CVE-2026-20127
An exploit for the Cisco Catalyst SD-WAN Controller authentication bypass vulnerability, CVE-2026-20127
★ 24 · 2026-03-09
randeepajayasekara/CVE-2026-20127
Walkthrough of the CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN from first malformed peering request to root on the management plane.
★ 0 · 2026-03-04
PoCs 16
★ 67
Last push 2026-07-10 (3 months ago)
Fetching description from NVD…
Show 8 of 16 repositories
gianlu111/CUPS-CVE-2024-47176
A Mass Scanner designed to detect the CVE-2024-47176 vulnerability across systems running the Common Unix Printing System (CUPS).
★ 1 · 2024-10-17
PoCs 17
★ 22
Last push 2026-07-10 (3 months ago)
Fetching description from NVD…
Show 8 of 17 repositories
echoosso/CVE-2019-9978
A Remote Code Execution (RCE) vulnerability in the Social Warfare plugin for WordPress, affecting versions below 3.5.3.
★ 1 · 2025-04-10
PoCs 7
★ 186
Last push 2026-07-09 (3 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 8
★ 35
Last push 2026-07-09 (3 months ago)
Fetching description from NVD…
Show 8 repositories
entra1337/DirtyClone
Python Proof of Concept for DirtyClone (CVE-2026-43503) - Linux kernel LPE via page-cache corruption
★ 26 · 2026-06-29
douglasmun/pagecache-lpe-containment-kit
Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, …
★ 3 · 2026-06-27
gl1tch0x1/DirtyClone
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
★ 2 · 2026-06-28
SecureWithUmer/CVE-2026-43503
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
★ 0 · 2026-06-29
PoCs 7
★ 41
Last push 2026-07-09 (3 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 5
★ 29
Last push 2026-07-08 (3 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 26
★ 1484
Last push 2026-07-08 (3 months ago)
Fetching description from NVD…
Show 8 of 26 repositories
Schira4396/VcenterKiller
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密…
★ 1484 · 2024-04-25
tunelko/CVE-2022-22954-PoC
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
★ 16 · 2024-02-13
PoCs 7
★ 12
Last push 2026-07-08 (3 months ago)
Fetching description from NVD…
Show 7 repositories
h3st4k3r/CVE-2025-30065
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It abuses the getDefaultValue() mechanism to instantia…
★ 7 · 2026-07-08
PoCs 6
★ 7
Last push 2026-07-07 (3 months ago)
Fetching description from NVD…
Show 6 repositories
PoCs 6
★ 1069
Last push 2026-07-07 (3 months ago)
Fetching description from NVD…
Show 6 repositories
Ridter/noPac
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
★ 1022 · 2023-01-29
ly4k/Pachine
Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)
★ 278 · 2022-01-13
xLTJ/noPac
Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287
★ 0 · 2026-07-07
PoCs 9
★ 23
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 29
★ 377
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 8 of 29 repositories
dsssssssm/WSOB
😭 WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
★ 26 · 2023-05-23
PoCs 12
★ 65
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 23
★ 50
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 8 of 23 repositories
PoCs 7
★ 4
Last push 2026-07-06 (3 months ago)
Fetching description from NVD…
Show 7 repositories
wubinworks/magento2-session-reaper-patch
Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a Magento 2 exte…
★ 4 · 2025-11-09
brito101/session_reaper_lab
Ambiente Docker para demonstração prática da CVE-2025-54236 (SessionReaper): PHP Object Deserialization levando a RCE em Magento Open Source 2.4.7
★ 0 · 2026-05-24
PoCs 5
★ 54
Last push 2026-07-05 (3 months ago)
Fetching description from NVD…
Show 5 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.