Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 7
★ 199
Last push 2026-07-03 (3 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
bp2008/DahuaLoginBypass
Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
★ 199 · 2026-07-03
PoCs 7
★ 3
Last push 2026-07-02 (3 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
Alisha-chaudhary/ssh-enum
This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration investigatio…
★ 0 · 2026-07-02
PoCs 55
★ 374
Last push 2026-07-01 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 of 55 repositories
PoCs 10
★ 22
Last push 2026-07-01 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 7
★ 11
Last push 2026-07-01 (3 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
PoCs 5
★ 4
Last push 2026-06-30 (3 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
PoCs 8
★ 20
Last push 2026-06-29 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
inteleon404/CVE-2025-0133
Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.
★ 11 · 2025-06-24
cruxN3T/CVE-2025-0133
Scope-aware bug bounty pipeline for CVE-2025-0133 (Palo Alto PAN-OS GlobalProtect reflected XSS). Shodan → H1/BC scope match → safe canary validation → report …
★ 0 · 2026-05-06
PoCs 15
★ 32
Last push 2026-06-29 (3 months, 1 week ago)
Fetching description from NVD…
Show 8 of 15 repositories
xeloxa/CVE-2026-23918-Apache-H2-PoC
Proof-of-Concept exploit for CVE-2026-23918 (Apache mod_http2 double-free). Features multi-mode DoS (Rapid-RST, Slow-Drip) and passive RCE/vulnerability detect…
★ 23 · 2026-05-06
qassam-315/CVE-2026-23918-Elite-Auditor
Elite reconnaissance script for auditing Apache's HTTP/2 stack against memory corruption (CVE-2026-23918). Features ALPN protocol forcing and monochrome dashbo…
★ 6 · 2026-05-05
12lie20/CVE-2026-23918-test
This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66 `mod_http2`.
★ 4 · 2026-05-05
hackervlogofficial/CVE-2026-23918
This is a proactive tool for security auditing. For your GitHub repository, you’ll want a description that highlights its safety (non-intrusive) and its specif…
★ 1 · 2026-05-06
PoCs 86
★ 1359
Last push 2026-06-26 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 86 repositories
PoCs 8
★ 323
Last push 2026-06-24 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 repositories
d3ndr1t30x/CVE-2022-37706
Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp directory; script h…
★ 1 · 2024-12-10
PoCs 5
★ 12
Last push 2026-06-23 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
CsEnox/CVE-2021-21425
GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)
★ 12 · 2023-04-18
PoCs 11
★ 12
Last push 2026-06-22 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 11 repositories
ZaleHack/joomla_rce_CVE-2015-8562
All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.
★ 8 · 2016-01-04
PoCs 10
★ 126
Last push 2026-06-21 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Mr-xn/CVE-2024-36991
Path Traversal On The "/Modules/Messaging/" Endpoint In Splunk Enterprise On Windows
★ 9 · 2024-07-06
gunzf0x/CVE-2024-36991
Proof of Concept for CVE-2024-36991. Path traversal for Splunk versions below 9.2.2, 9.1.5, and 9.0.10 for Windows which allows arbitrary file read.
★ 4 · 2025-03-31
0xFZin/CVE-2024-36991
Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed.
★ 3 · 2026-06-21
th3gokul/CVE-2024-36991
CVE-2024-36991: Path traversal that affects Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10.
★ 2 · 2024-07-06
TheStingR/CVE-2024-36991-Tool
This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive files and…
★ 2 · 2025-10-30
PoCs 6
★ 7
Last push 2026-06-21 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 14
★ 84
Last push 2026-06-20 (3 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
dragonked2/CVE-2024-50379-POC
This repository contains a Python script designed to exploit CVE-2024-50379, a vulnerability that allows attackers to upload a JSP shell to a vulnerable server…
★ 4 · 2024-12-25
pwnosec/CVE-2024-50379
ExploitDB CVE-2024-50379 a vulnerability that enables attackers to upload a JSP shell to a vulnerable server and execute commands remotely. The exploit is espe…
★ 2 · 2025-01-23
PoCs 33
★ 126
Last push 2026-06-19 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 18
★ 18
Last push 2026-06-19 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 18 repositories
Alien0ne/CVE-2025-2304
Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.
★ 18 · 2026-02-04
d3vn0mi/CVE-2025-2304-POC
Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.
★ 10 · 2026-05-01
CsuriBird/CVE-2025-2304
This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their privileges t…
★ 5 · 2026-02-19
PoCs 6
★ 7
Last push 2026-06-18 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 6
★ 8
Last push 2026-06-17 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
0xbassiouny1337/CVE-2024-42009
This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail system, wh…
★ 4 · 2025-02-12
Bhanunamikaze/CVE-2024-42009
This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from a target w…
★ 1 · 2025-03-03
PoCs 5
★ 39
Last push 2026-06-17 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
PoCs 19
★ 135
Last push 2026-06-16 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 10
★ 527
Last push 2026-06-16 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Admin9961/CVE-2024-30088
Questa repository contiene una replica (tentativo di replica) scritto in Python per CVE-2024-30088.
★ 2 · 2024-07-27
PoCs 6
★ 80
Last push 2026-06-15 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
qixils/AntiCropalypse
Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images
★ 22 · 2023-04-01
lordofpipes/acropadetect
Web tool for detecting Acropalypse (CVE-2023-21036) https://lordofpipes.github.io/acropadetect/
★ 3 · 2023-04-01
PoCs 7
★ 30
Last push 2026-06-15 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
sfewer-r7/CVE-2026-0257
Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257
★ 30 · 2026-05-29
tushargurav28/CVE-2026-0257
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized V…
★ 3 · 2026-06-03
grayxploit/CVE-2026-0257
GrayXploit Security research and defensive team validate this toolkit for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass). Includes vulnerability as…
★ 1 · 2026-06-10
PoCs 13
★ 48
Last push 2026-06-14 (3 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
imnotcha0s/CVE-2024-10914
Exploit for cve-2024-10914: D-Link DNS-320, DNS-320LW, DNS-325, DNS-340L Version 1.00, Version 1.01.0914.2012, Version 1.01, Version 1.02, Version 1.08 Command…
★ 15 · 2024-11-09
ThemeHackers/CVE-2024-10914
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
★ 9 · 2025-06-09
TH-SecForge/CVE-2024-10914
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
★ 1 · 2025-06-09
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.