Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 6
★ 120
Last push 2026-06-12 (3 months, 4 weeks ago)
Fetching description from NVD…
Show 6 repositories
hacefresko/CVE-2021-4045
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
★ 120 · 2024-10-31
0xbinder/CVE-2021-4045
🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓
★ 9 · 2023-12-27
234329a423853/CVE-2021-4045
CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all firmware …
★ 1 · 2025-12-11
PoCs 14
★ 506
Last push 2026-06-11 (3 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 15
★ 140
Last push 2026-06-09 (4 months ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 6
★ 46
Last push 2026-06-07 (4 months ago)
Fetching description from NVD…
Show 6 repositories
CaptainChicky/MiniPlasma
CVE-2020-17103 was apparently not patched or the patch was reversed, regardless this the PoC for an LPE in cldflt.sys
★ 3 · 2026-05-16
PoCs 8
★ 41
Last push 2026-06-07 (4 months ago)
Fetching description from NVD…
Show 8 repositories
PoCs 15
★ 332
Last push 2026-06-06 (4 months ago)
Fetching description from NVD…
Show 8 of 15 repositories
0xbinder/CVE-2024-0044
CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13
★ 332 · 2024-12-02
canyie/CVE-2024-0044
RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation from adb to i…
★ 180 · 2024-09-30
sridhar-sec/EvilDroid
EvilDroid automates the exploitation of CVE-2024-0044, installing malicious payloads on a target device and extracting sensitive data. It features automated AD…
★ 31 · 2025-09-06
007CRIPTOGRAFIA/c-CVE-2024-0044
CVE-2024-0044: uma vulnerabilidade de alta gravidade do tipo "executar como qualquer aplicativo" que afeta as versões 12 e 13 do Android
★ 4 · 2024-07-11
PoCs 5
★ 6
Last push 2026-06-04 (4 months ago)
Fetching description from NVD…
Show 5 repositories
ayushghatkar8080/MadeYouReset_Tester
A Python script that checks if a web server is vulnerable to MadeYouReset (CVE-2025-8671) — an HTTP/2 DoS attack that bypasses Rapid Reset mitigations by trick…
★ 4 · 2026-06-04
abiyeenzo/CVE-2025-8671
PoC éducatif pour la vulnérabilité CVE-2025-8671 (DoS HTTP/2 sur lighttpd). À utiliser uniquement en laboratoire local.
★ 0 · 2025-08-23
PoCs 5
★ 17
Last push 2026-06-04 (4 months ago)
Fetching description from NVD…
Show 5 repositories
kyakei/CVE-2025-4138-poc
A Python script to generate a malicious tar archive that exploits CVE-2025-4138 / CVE-2025-4517.
★ 1 · 2026-02-16
localh0ste/CVE-2025-4138
Tarfile module directory traversal vulnerability ( with overflow crossed Directory ) --> Lead to Privilege escalation
★ 0 · 2026-02-17
d3vn0mi/CVE-2025-4138-POC
Python PoC for CVE-2025-4138, a path traversal in Python's tarfile module abusing symlink chains to bypass PATH_MAX for arbitrary file write
★ 0 · 2026-02-22
PoCs 8
★ 5
Last push 2026-06-03 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
josal/crack-0.1.8-fixed
crack repo from jnunemaker but with version 0.1.8 and rails CVE-2013-0156 vulnerability fixed
★ 0 · 2013-01-11
oxben10/CVE-2013-0156
This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit
★ 0 · 2024-11-13
PoCs 5
★ 16
Last push 2026-06-01 (4 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
PoCs 11
★ 71
Last push 2026-05-31 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 of 11 repositories
PoCs 10
★ 9
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
0xgh057r3c0n/CVE-2025-6934
CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new administrator …
★ 5 · 2025-08-17
PoCs 8
★ 13
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
Chocapikk/CVE-2023-5360
Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.
★ 10 · 2023-11-02
Pushkarup/CVE-2023-5360
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to u…
★ 5 · 2023-11-05
PoCs 8
★ 86
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
PoCs 6
★ 34
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
PoCs 7
★ 267
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
mpgn/poodle-PoC
:poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle:
★ 267 · 2023-10-06
PoCs 9
★ 41
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 of 9 repositories
Rubikcuv5/cve-2023-30253
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
★ 7 · 2024-05-26
PoCs 18
★ 49
Last push 2026-05-30 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 of 18 repositories
BridgerAlderson/CVE-2025-9074-PoC
A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targete…
★ 49 · 2025-12-07
OilSeller2001/PoC-for-CVE-2025-9074
Proof-of-Concept exploit for CVE-2025-9074 - Unauthenticated Docker API exposure allowing arbitrary container creation and host filesystem access.
★ 4 · 2025-10-06
xwpdx0/poc-2025-9074
Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API endpoints with …
★ 4 · 2025-12-09
PoCs 9
★ 80
Last push 2026-05-29 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 8
★ 37
Last push 2026-05-28 (4 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
keraattin/CVE-2026-35616
CVE-2026-35616 - FortiClient EMS Pre-Authentication API Bypass (CVSS 9.1, CISA KEV). Python & Nmap NSE detection scripts with full technical breakdown. One for…
★ 1 · 2026-04-13
PoCs 5
★ 7
Last push 2026-05-27 (4 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
her3ticAVI/CVE-2023-35813
CVE-2023-35813 is a proof-of-concept used to determine if an instance of Sitecore is vulnerable by analyzing a server Response Header for modification.
★ 3 · 2026-03-27
PoCs 7
★ 11
Last push 2026-05-26 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
ownouwa/cve-2024-23113-poc
CVE-2024-23113 是一个在 Linux Kernel 中被发现的漏洞,它属于 任意代码执行漏洞,影响了 bpf (Berkeley Packet Filter) 子系统。具体来说,这个漏洞影响了 bpf 程序的 bpf_prog 类型的对象,并且可以允许攻击者通过构造恶意的 BPF 程序来在内核空间执行恶…
★ 0 · 2024-11-28
iambrayden/CVE-2024-23113
This python scripts searches a client list to see if their FortiGate device is vulnerable to this CVE.
★ 0 · 2025-05-02
PoCs 18
★ 42
Last push 2026-05-25 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 18 repositories
PoCs 6
★ 5
Last push 2026-05-24 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 74
Last push 2026-05-23 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.