Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2020-1938
FRESH PoCHOTMULTI PoC
PoCs 40 ★ 422 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
00theway/Ghostcat-CNVD-2020-10487

Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)

★ 422 · 2020-03-09
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner

Cnvd-2020-10487 / cve-2020-1938, scanner tool

★ 294 · 2021-11-26
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read

Tomcat的文件包含及文件读取漏洞利用POC

★ 57 · 2020-02-21
xindongzhuaizhuai/CVE-2020-1938
★ 45 · 2020-03-02
laolisafe/CVE-2020-1938

CVE-2020-1938漏洞复现

★ 38 · 2020-02-21
CVE-2017-12615
FRESH PoCHOTMULTI PoC
PoCs 18 ★ 295 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 18 repositories
lizhianyuguangming/TomcatScanPro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

★ 295 · 2026-06-16
tpt11fb/AttackTomcat

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

★ 257 · 2022-11-15
breaktoprotect/CVE-2017-12615

POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.

★ 112 · 2022-10-09
mefulton/cve-2017-12615

just a python script for cve-2017-12615

★ 11 · 2017-10-01
xiaokp7/Tomcat_PUT_GUI_EXP

Tomcat PUT方法任意文件写入(CVE-2017-12615)exp

★ 11 · 2023-03-14
zi0Black/POC-CVE-2017-12615-or-CVE-2017-12717

CVE-2017-12617 and CVE-2017-12615 for tomcat server

★ 6 · 2017-10-10
1337g/CVE-2017-12615

CVE-2017-12615 Tomcat RCE (TESTED)

★ 4 · 2017-12-26
wsg00d/cve-2017-12615

tomcat-put-cve-2017-12615

★ 3 · 2017-11-01
CVE-2023-27524
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 113 Last push 2026-10-09 (21 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 15 repositories
horizon3ai/CVE-2023-27524

Basic PoC for CVE-2023-27524: Insecure Default Configuration in Apache Superset

★ 113 · 2023-09-09
Okaytc/Superset_auth_bypass_check

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

★ 11 · 2023-08-03
tardc/CVE-2023-27524

Apache Superset Auth Bypass (CVE-2023-27524)

★ 10 · 2023-05-09
ZZ-SOCMAP/CVE-2023-27524

Apache Superset Auth Bypass Vulnerability CVE-2023-27524.

★ 3 · 2023-04-27
Ap0dexMe0/CVE-2023-27524

Perform With Apache-SuperSet Leaked Token [CSRF]

★ 3 · 2023-07-24
Cappricio-Securities/CVE-2023-27524

Apache Superset - Authentication Bypass

★ 2 · 2024-06-24
karthi-the-hacker/CVE-2023-27524

Tool for finding CVE-2023-27524 (Apache Superset - Authentication Bypass)

★ 1 · 2024-05-11
CVE-2022-22965
FRESH PoCHOTMULTI PoC
PoCs 99 ★ 376 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 99 repositories
BobTheShoplifter/Spring4Shell-POC

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

★ 376 · 2022-11-09
reznok/Spring4Shell-POC

Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit

★ 325 · 2022-08-04
tpt11fb/SpringVulScan

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

★ 155 · 2023-01-23
TheGejr/SpringShell

Spring4Shell - Spring Core RCE - CVE-2022-22965

★ 131 · 2022-04-04
zangcc/CVE-2022-22965-rexbb

CVE-2022-22965\Spring-Core-RCE核弹级别漏洞的rce图形化GUI一键利用工具,基于JavaFx开发,图形化操作更简单,提高效率。

★ 102 · 2023-11-14
alt3kx/CVE-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

★ 100 · 2022-04-07
SecNN/SpringFramework_CVE-2022-22965_RCE

SpringFramework 远程代码执行漏洞CVE-2022-22965

★ 72 · 2022-04-01
4nth0ny1130/spring4shell_behinder

CVE-2022-22965写入冰蝎webshell脚本

★ 62 · 2022-05-10
CVE-2022-22963
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 353 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
hktalent/spring-spel-0day-poc

spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963

★ 353 · 2023-03-05
dinosn/CVE-2022-22963

CVE-2022-22963 PoC

★ 116 · 2022-03-30
darryk10/CVE-2022-22963
★ 34 · 2022-04-15
J0ey17/CVE-2022-22963_Reverse-Shell-Exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vuln…

★ 24 · 2023-03-18
me2nuk/CVE-2022-22963

Spring Cloud Function Vulnerable Application / CVE-2022-22963

★ 19 · 2022-04-01
RanDengShiFu/CVE-2022-22963

CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit

★ 15 · 2022-03-30
kh4sh3i/Spring-CVE

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed …

★ 14 · 2022-03-31
Kirill89/CVE-2022-22963-PoC
★ 9 · 2022-03-30
CVE-2022-22947
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 223 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 62 repositories
lucksec/Spring-Cloud-Gateway-CVE-2022-22947

CVE-2022-22947

★ 223 · 2022-03-03
whwlsfb/cve-2022-22947-godzilla-memshell

CVE-2022-22947 注入Godzilla内存马

★ 208 · 2022-04-26
SecNN/CVE-2022-22947_Rce_Exp

Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947

★ 77 · 2022-11-14
tangxiaofeng7/CVE-2022-22947-Spring-Cloud-Gateway

CVE-2022-22947批量

★ 71 · 2022-03-04
0730Nophone/CVE-2022-22947-

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

★ 59 · 2022-05-16
crowsec-edtech/CVE-2022-22947

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

★ 37 · 2022-03-04
0x7eTeam/CVE-2022-22947

CVE-2022-22947_EXP,CVE-2022-22947_RCE,CVE-2022-22947反弹shell,CVE-2022-22947 getshell

★ 35 · 2022-03-08
Tas9er/SpringCloudGatewayRCE

SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er

★ 27 · 2022-03-03
CVE-2018-1273
FRESH PoCMULTI PoC
PoCs 7 ★ 58 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 7 repositories
jas502n/cve-2018-1273

Spring Data Commons RCE 远程命令执行漏洞

★ 58 · 2019-04-29
wearearima/poc-cve-2018-1273

POC for CVE-2018-1273

★ 24 · 2018-06-05
knqyf263/CVE-2018-1273

Environment for CVE-2018-1273 (Spring Data Commons)

★ 10 · 2018-08-15
webr0ck/poc-cve-2018-1273
★ 2 · 2018-10-05
cved-sources/cve-2018-1273

cve-2018-1273

★ 0 · 2021-04-15
hdgokani/CVE-2018-1273
★ 0 · 2025-06-25
CyberCTF/vulhub-spring-cve-2018-1273

Vulhub spring/CVE-2018-1273: Spring Data Commons SpEL Injection (CVE-2018-1273), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-17558
FRESH PoCHOTMULTI PoC
PoCs 6 ★ 4291 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 6 repositories
zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…

★ 4291 · 2021-04-04
Ma1Dong/Solr_CVE-2019-17558

Solr_CVE-2019-17558

★ 2 · 2020-08-04
thelostworldFree/CVE-2019-17558_Solr_Vul_Tool

CVE-2019-17558 Solr模板注入漏洞图形化一键检测工具。CVE-2019-17558 Solr Velocity Template Vul POC Tool.

★ 1 · 2020-01-10
xkyrage/Exploit_CVE-2019-17558-RCE

Apache Solr 1.4 Injection to get a shell

★ 0 · 2020-12-15
CyberCTF/vulhub-solr-cve-2019-17558

Vulhub solr/CVE-2019-17558: Apache Solr Velocity Template RCE (CVE-2019-17558), run with Isoloom

★ 0 · 2026-10-09
CVE-2016-4437
FRESH PoCMULTI PoC
PoCs 7 ★ 55 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 7 repositories
bkfish/Awesome_shiro

CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本

★ 55 · 2020-06-27
4nth0ny1130/shisoserial

一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.

★ 24 · 2022-07-06
pizza-power/CVE-2016-4437

Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key

★ 2 · 2024-06-29
35789-gh/cve-2016-4437

这是基于cve-2016-4437简单的漏洞复现代码

★ 1 · 2026-02-19
m3terpreter/CVE-2016-4437
★ 0 · 2021-06-22
xk-mt/CVE-2016-4437

1.验证CVE-2016-4437、2.解析rememberMe的文件和CBC加密的IV偏移

★ 0 · 2024-01-16
CyberCTF/vulhub-shiro-cve-2016-4437

Vulhub shiro/CVE-2016-4437: Shiro 1.2.4 rememberMe deserialization, run with Isoloom

★ 0 · 2026-10-09
CVE-2017-7494
FRESH PoCHOTMULTI PoC
PoCs 22 ★ 380 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 22 repositories
opsxcq/exploit-CVE-2017-7494

SambaCry exploit and vulnerable container (CVE-2017-7494)

★ 380 · 2022-12-27
joxeankoret/CVE-2017-7494

Remote root exploit for the SAMBA CVE-2017-7494 vulnerability

★ 259 · 2021-03-09
betab0t/cve-2017-7494

Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)

★ 181 · 2017-07-26
Waffles-2/SambaCry

CVE-2017-7494 - Detection Scripts

★ 63 · 2017-05-26
brianwrf/SambaHunter

It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).

★ 58 · 2021-10-31
d3fudd/CVE-2017-7494_SambaCry

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

★ 7 · 2022-11-01
0xm4ud/noSAMBAnoCRY-CVE-2017-7494

CVE-2017-7494 python exploit

★ 5 · 2021-08-27
I-Rinka/BIT-EternalBlue-for-macOS_Linux

Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.

★ 4 · 2021-05-18
CVE-2020-11651
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 121 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 15 repositories
jasperla/CVE-2020-11651-poc

PoC exploit of CVE-2020-11651 and CVE-2020-11652

★ 121 · 2020-07-10
rossengeorgiev/salt-security-backports

Salt security backports for CVE-2020-11651 & CVE-2020-11652

★ 108 · 2020-05-18
dozernz/cve-2020-11651
★ 106 · 2020-05-04
0xc0d/CVE-2020-11651

CVE-2020-11651: Proof of Concept

★ 40 · 2021-07-07
ssrsec/CVE-2020-11651-CVE-2020-11652-EXP

CVE-2020-11651&&CVE-2020-11652 EXP

★ 24 · 2023-03-21
chef-cft/salt-vulnerabilities

Checks for CVE-2020-11651 and CVE-2020-11652

★ 6 · 2021-08-24
kevthehermit/CVE-2020-11651

PoC for CVE-2020-11651

★ 6 · 2020-05-04
bravery9/SaltStack-Exp

CVE-2020-11651&&CVE-2020-11652 EXP

★ 5 · 2020-05-04
CVE-2022-0543
FRESH PoCMULTI PoC
PoCs 6 ★ 95 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 6 repositories
0x7eTeam/CVE-2022-0543

CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行

★ 95 · 2024-01-16
z92g/CVE-2022-0543

Redis 沙盒逃逸(CVE-2022-0543)POC&EXP

★ 23 · 2022-07-23
SiennaSkies/redisHack

redis未授权、redis_CVE-2022-0543检测利用二合一脚本

★ 3 · 2023-05-11
fulxey/CVE-2022-0543

Redis RCE through Lua Sandbox Escape vulnerability

★ 1 · 2022-09-02
netw0rk7/CVE-2022-0543-Home-Lab

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

★ 0 · 2025-12-01
CyberCTF/vulhub-redis-cve-2022-0543

Vulhub redis/CVE-2022-0543: Redis Lua Sandbox Escape (CVE-2022-0543), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-5418
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 201 Last push 2026-10-09 (21 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
mpgn/CVE-2019-5418

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

★ 201 · 2021-04-05
mpgn/Rails-doubletap-RCE

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

★ 132 · 2023-01-19
brompwnie/CVE-2019-5418-Scanner

A multi-threaded Golang scanner to identify Ruby endpoints vulnerable to CVE-2019-5418

★ 36 · 2019-03-21
omarkurt/CVE-2019-5418

File Content Disclosure on Rails Test Case - CVE-2019-5418

★ 5 · 2019-03-18
random-robbie/CVE-2019-5418
★ 5 · 2019-11-19
Bad3r/RailroadBandit

a demo for Ruby on Rails CVE-2019-5418

★ 3 · 2019-04-11
kailing0220/CVE-2019-5418

Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再…

★ 2 · 2022-10-17
ztgrace/CVE-2019-5418-Rails3

Rails 3 PoC of CVE-2019-5418

★ 0 · 2023-07-13
CVE-2019-9193
FRESH PoCMULTI PoC
PoCs 9 ★ 21 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 9 repositories
b4keSn4ke/CVE-2019-9193

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

★ 21 · 2022-05-26
geniuszly/CVE-2019-9193

is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)

★ 4 · 2024-10-06
wkjung0624/cve-2019-9193

PostgreSQL Remote Code Executuon

★ 3 · 2021-04-16
paulotrindadec/CVE-2019-9193
★ 1 · 2023-02-01
jhnhnck/CVE-2019-9193

PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)

★ 0 · 2026-09-11
netw0rk7/CVE-2019-9193-Home-Lab

This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE

★ 0 · 2025-12-01
CVE-2017-9841
FRESH PoCMULTI PoC
PoCs 18 ★ 30 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 18 repositories
RandomRobbieBF/phpunit-brute

Tool to try multiple paths for PHPunit RCE CVE-2017-9841

★ 30 · 2021-10-18
incogbyte/laravel-phpunit-rce-masscaner

Masscanner for Laravel phpunit RCE CVE-2017-9841

★ 23 · 2021-08-10
Chocapikk/CVE-2017-9841

PHPUnit RCE

★ 7 · 2026-01-16
ludy-dev/PHPUnit_eval-stdin_RCE

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

★ 6 · 2020-11-07
MadExploits/PHPunit-Exploit

PHPunit Checker CVE-2017-9841 By MrMad

★ 5 · 2023-02-04
MrG3P5/CVE-2017-9841

A Tool for scanning CVE-2017-9841 with multithread

★ 4 · 2024-02-15
drcrypterdotru/PHPUnit-GoScan

PHPUnit CVE-2017-9841 Scanner in Go clean and fire.

★ 4 · 2025-08-30
akr3ch/CVE-2017-9841

RCE exploit for PHP Unit 5.6.2

★ 3 · 2022-08-19
CVE-2025-14847
FRESH PoCMULTI PoC
PoCs 40 ★ 35 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
Black1hp/mongobleed-scanner

MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool

★ 35 · 2025-12-28
cybertechajju/CVE-2025-14847_Expolit

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…

★ 34 · 2025-12-27
ProbiusOfficial/CVE-2025-14847

poc for CVE-2025-14847

★ 26 · 2025-12-26
onewinner/CVE-2025-14847

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

★ 15 · 2025-12-26
Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

★ 13 · 2026-01-03
codeb0ssx/CVE-2025-14847-PoC

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

★ 4 · 2025-12-29
joshuavanderpoll/CVE-2025-14847

CVE-2025-14847 (MongoBleed)

★ 4 · 2025-12-29
franksec42/mongobleed-exploit-CVE-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

★ 3 · 2026-02-20
CVE-2019-11043
FRESH PoCHOTMULTI PoC
PoCs 28 ★ 1833 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 28 repositories
neex/phuip-fpizdam

Exploit for CVE-2019-11043

★ 1833 · 2019-11-12
theMiddleBlue/CVE-2019-11043

(PoC) Python version of CVE-2019-11043 exploit by neex

★ 147 · 2019-10-29
jas502n/CVE-2019-11043

php-fpm+Nginx RCE

★ 105 · 2020-08-20
akamajoris/CVE-2019-11043-Docker
★ 27 · 2019-10-28
k8gege/CVE-2019-11043

Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)

★ 16 · 2019-11-11
0th3rs-Security-Team/CVE-2019-11043

CVE-2019-11043 PHP7.x RCE

★ 14 · 2019-11-06
kriskhub/CVE-2019-11043

This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.

★ 14 · 2020-05-25
ypereirareis/docker-CVE-2019-11043

Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.

★ 8 · 2019-10-30
CVE-2012-1823
FRESH PoCMULTI PoC
PoCs 16 ★ 12 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 16 repositories
0xl0k1/CVE-2012-1823

PHP CGI Argument Injection.

★ 12 · 2023-08-24
Unix13/metasploitable2

PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured…

★ 4 · 2018-07-11
tardummy01/oscp_scripts-1

First script, pgp-cgi-cve-2012-1823 BASH script

★ 3 · 2017-03-22
drone789/CVE-2012-1823
★ 1 · 2015-09-08
cyberharsh/PHP_CVE-2012-1823
★ 1 · 2020-08-17
Dmitri131313/CVE-2012-1823-exploit-for-https-user-password-web

CVE-2012-1823 exploit for https user password website.

★ 1 · 2025-02-19
hackherMind-Pixel/Vulnerable-Lab-Exploitation

A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.

★ 1 · 2026-01-22
mujtaba815/metasploitable2-php-cgi-exploit

Exploited a known RCE vulnerability (PHP-CGI Argument Injection, CVE-2012-1823) on Metasploitable2 using Metasploit Framework, gained a shell, and documented p…

★ 1 · 2026-10-02
CVE-2014-0160
FRESH PoCHOTMULTI PoC
PoCs 73 ★ 2373 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 73 repositories
FiloSottile/Heartbleed

A checker (site and tool) for CVE-2014-0160

★ 2373 · 2021-02-24
musalbas/heartbleed-masstest

Multi-threaded tool for scanning many hosts for CVE-2014-0160.

★ 571 · 2015-07-02
titanous/heartbleeder

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

★ 452 · 2014-05-27
Lekensteyn/pacemaker

Heartbleed (CVE-2014-0160) client exploit

★ 331 · 2016-01-22
sensepost/heartbleed-poc

Test for SSL heartbeat vulnerability (CVE-2014-0160)

★ 171 · 2014-07-10
einaros/heartbleed-tools

OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.

★ 98 · 2014-06-18
mpgn/heartbleed-PoC

:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:

★ 85 · 2021-02-20
isgroup/openmagic

OpenSSL TLS heartbeat read overrun (CVE-2014-0160)

★ 40 · 2014-04-11
CVE-2018-15473
FRESH PoCHOTMULTI PoC
PoCs 42 ★ 533 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 42 repositories
Rhynorater/CVE-2018-15473-Exploit

Exploit written in Python for CVE-2018-15473 with threading and export formats

★ 533 · 2024-07-12
trimstray/massh-enum

OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).

★ 160 · 2019-11-15
epi052/cve-2018-15473

Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473

★ 117 · 2024-04-29
Sait-Nuri/CVE-2018-15473

OpenSSH 2.3 < 7.7 - Username Enumeration

★ 42 · 2023-09-04
r3dxpl0it/CVE-2018-15473

OpenSSH 7.7 - Username Enumeration

★ 17 · 2020-10-23
sergiovks/SSH-User-Enum-Python3-CVE-2018-15473

SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of …

★ 4 · 2023-03-12
gbonacini/opensshenum

CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug

★ 3 · 2018-10-17
MrDottt/CVE-2018-15473

CVE-2018-15473 Exploit

★ 3 · 2021-09-14
CVE-2020-7247
FRESH PoCMULTI PoC
PoCs 11 ★ 25 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
FiroSolutions/cve-2020-7247-exploit

Python exploit of cve-2020-7247

★ 25 · 2020-02-19
QTranspose/CVE-2020-7247-exploit

OpenSMTPD 6.4.0 - 6.6.1 Remote Code Execution PoC exploit

★ 11 · 2021-02-17
r0lh/CVE-2020-7247

Proof Of Concept Exploit for CVE-2020-7247 (Remote Execution on OpenSMTPD < 6.6.2

★ 5 · 2020-02-18
superzerosec/cve-2020-7247

OpenSMTPD version 6.6.2 remote code execution exploit

★ 4 · 2022-01-15
SimonSchoeni/CVE-2020-7247-POC

Proof of concept for CVE-2020-7247 for educational purposes.

★ 2 · 2022-01-20
presentdaypresenttime/shai_hulud

Worm written in python, abuses CVE-2020-7247

★ 2 · 2022-05-17
f4T1H21/CVE-2020-7247

PoC exploit for CVE-2020-7247 OpenSMTPD 6.4.0 < 6.6.1 Remote Code Execution

★ 2 · 2021-07-10
CVE-2023-32315
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 142 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
miko550/CVE-2023-32315

Openfire Console Authentication Bypass Vulnerability with RCE plugin

★ 61 · 2024-03-07
Ap0dexMe0/CVE-2023-32315

Perform With Massive Openfire Unauthenticated Users

★ 7 · 2023-07-24
izzz0/CVE-2023-32315-POC

CVE-2023-32315-Openfire-Bypass

★ 5 · 2023-07-11
gibran-abdillah/CVE-2023-32315

Tool for CVE-2023-32315 exploitation

★ 3 · 2023-08-31
ohnonoyesyes/CVE-2023-32315
★ 0 · 2023-06-14
CN016/Openfire-RCE-CVE-2023-32315-

Openfire未授权到RCE(CVE-2023-32315)复现

★ 0 · 2023-10-10
CVE-2023-51467
FRESH PoCMULTI PoC
PoCs 8 ★ 73 Last push 2026-10-09 (21 hours, 25 minutes ago)

Fetching description from NVD…

Show 8 repositories
jakabakos/Apache-OFBiz-Authentication-Bypass

This repo is a PoC with to exploit CVE-2023-51467 and CVE-2023-49070 preauth RCE vulnerabilities found in Apache OFBiz.

★ 73 · 2024-03-24
Chocapikk/CVE-2023-51467

Apache OfBiz Auth Bypass Scanner for CVE-2023-51467

★ 12 · 2023-12-31
vulncheck-oss/cve-2023-51467

A go-exploit for Apache OFBiz CVE-2023-51467

★ 6 · 2025-02-14
ImuSpirit/CVE-2023-51467

CVE-2023-51467 POC

★ 4 · 2024-01-02
Subha-BOO7/Exploit_CVE-2023-51467
★ 0 · 2024-01-04
jakeotte/BadBizness-CVE-2023-51467

Auto exploit script for the Java web framework OF Biz under CVE-2023-51467.

★ 0 · 2024-01-13
AhmedMansour93/Event-ID-217-Rule-Name-SOC254-Apache-OFBiz-Auth-Bypass-and-Code-Injection-0Day-CVE-2023-51467-

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability allows att…

★ 0 · 2024-09-13
CyberCTF/vulhub-ofbiz-cve-2023-51467

Vulhub ofbiz/CVE-2023-51467: Apache OFBiz Authentication Bypass to RCE (CVE-2023-51467), run with Isoloom

★ 0 · 2026-10-09
CVE-2017-7529
FRESH PoCMULTI PoC
PoCs 18 ★ 19 Last push 2026-10-09 (21 hours, 26 minutes ago)

Fetching description from NVD…

Show 8 of 18 repositories
en0f/CVE-2017-7529_PoC

CVE-2017-7529_PoC

★ 19 · 2026-01-07
liusec/CVE-2017-7529
★ 16 · 2017-07-21
gemboxteam/exploit-nginx-1.10.3

CVE-2017-7529 | nginx on the range 0.5.6 - 1.13.2

★ 12 · 2021-01-19
Shehzadcyber/CVE-2017-7529

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of pote…

★ 11 · 2022-07-18
MaxSecurity/CVE-2017-7529-POC
★ 4 · 2019-06-06
cyberharsh/nginx-CVE-2017-7529
★ 2 · 2020-07-02
mo3zj/Nginx-Remote-Integer-Overflow-Vulnerability

CVE-2017-7529

★ 1 · 2021-03-31
coolman6942o/-Exploit-CVE-2017-7529

CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting in…

★ 1 · 2023-12-19
CVE-2012-2122
FRESH PoCMULTI PoC
PoCs 5 ★ 1 Last push 2026-10-09 (21 hours, 26 minutes ago)

Fetching description from NVD…

Show 5 repositories
Avinza/CVE-2012-2122-scanner

This is used to scan for CVE-2012-2122 vulnerable servers.

★ 1 · 2013-05-09
zhangkaibin0921/CVE-2012-2122
★ 0 · 2023-12-01
netw0rk7/CVE-2012-2122-Home-Lab

CVE-2012-2122 MySQL Authentication Bypass Home Lab

★ 0 · 2025-12-01
CyberCTF/vulhub-mysql-cve-2012-2122

Vulhub mysql/CVE-2012-2122: MySQL Authentication Bypass (CVE-2012-2122), run with Isoloom

★ 0 · 2026-10-09
< Prev Page 2 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.