Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
803 results
PoCs 7
★ 269
Last push 2026-05-21 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
st-rnd/desc_race-1
desc_race exploit for iOS 15.0 - 15.1.1 (with stable kernel r/w primitives) (CVE-2021-30955)
★ 0 · 2022-03-15
PoCs 6
★ 134
Last push 2026-05-21 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 77
Last push 2026-05-21 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
PoCs 6
★ 1
Last push 2026-05-21 (4 months, 2 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 10
★ 40
Last push 2026-05-19 (4 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Mafiosohack/offensive-security-lab-1
A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation with Meta…
★ 0 · 2025-06-17
PoCs 6
★ 137
Last push 2026-05-19 (4 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 7
★ 140
Last push 2026-05-17 (4 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
Occamsec/CVE-2023-2825
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
★ 140 · 2023-06-02
Groppoxx/CVE-2023-2825-PoC
PoC for CVE-2023-2825: automated GitLab 16.0.0 arbitrary file read via nested public groups, project upload traversal, reusable upload paths, and clean CLI out…
★ 4 · 2026-05-17
Tornad0007/CVE-2023-2825-Gitlab
the proof of concept written in Python for an unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when …
★ 0 · 2023-05-30
Rubikcuv5/CVE-2023-2825
On May 23, 2023 GitLab released version 16.0.1 which fixed a critical vulnerability, CVE-2023-2825, affecting the Community Edition (CE) and Enterprise Edition…
★ 0 · 2023-06-17
PoCs 23
★ 98
Last push 2026-05-16 (4 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 23 repositories
3ndG4me/CVE-2020-3452-Exploit
Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.
★ 24 · 2020-10-10
murataydemir/CVE-2020-3452
[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
★ 8 · 2020-09-16
PoCs 13
★ 21
Last push 2026-05-13 (4 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
PoCs 5
★ 26
Last push 2026-05-12 (4 months, 4 weeks ago)
Fetching description from NVD…
Show 5 repositories
NULL200OK/cve_2026_34621_advanced
A sophisticated, cross-platform exploit generator for **CVE-2026-34621** – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads …
★ 13 · 2026-04-15
PoCs 27
★ 5
Last push 2026-05-12 (4 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 27 repositories
Rai2en/CVE-2023-4220-Chamilo-LMS
This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220
★ 5 · 2026-02-09
Ziad-Sakr/Chamilo-CVE-2023-4220-Exploit
This is an Exploit for Unrestricted file upload in big file upload functionality in Chamilo-LMS for this location "/main/inc/lib/javascript/bigupload/inc/bigUp…
★ 5 · 2024-07-08
PoCs 15
★ 3
Last push 2026-05-11 (4 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 20
★ 105
Last push 2026-05-11 (4 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 20 repositories
PoCs 10
★ 59
Last push 2026-05-10 (5 months ago)
Fetching description from NVD…
Show 8 of 10 repositories
E1tex/Python-CVE-2020-25213
Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upl…
★ 3 · 2023-08-02
PoCs 19
★ 66
Last push 2026-05-08 (5 months ago)
Fetching description from NVD…
Show 8 of 19 repositories
gotr00t0day/CVE-2024-4040
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to…
★ 7 · 2024-05-04
PoCs 19
★ 22
Last push 2026-05-07 (5 months ago)
Fetching description from NVD…
Show 8 of 19 repositories
Diefunction/CVE-2019-10149
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/del…
★ 20 · 2021-06-04
PoCs 10
★ 9
Last push 2026-05-06 (5 months ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 11
★ 12
Last push 2026-05-06 (5 months ago)
Fetching description from NVD…
Show 8 of 11 repositories
0p5cur/CVE-2025-32462-POC
🔓 Local privilege escalation PoC for CVE-2025-32462 (sudo -h bypass) – gain root via misconfigured sudoers
★ 9 · 2026-02-17
j3r1ch0123/CVE-2025-32462
The vulnerability was found by Rich Mirch. More details on it here: https://cxsecurity.com/issue/WLB-2025070022
★ 1 · 2025-07-28
PoCs 6
★ 31
Last push 2026-05-04 (5 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
dinosn/proftpd-CVE-2026-42167-analysis
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).
★ 3 · 2026-04-29
PoCs 6
★ 38
Last push 2026-05-02 (5 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
SoftAndoWetto/CVE-2025-24367-PoC-Cacti
Authenticated RCE PoC for Cacti (CVE‑2025‑24367). Uses graph template injection to write and execute a payload via the “Unix – Logged in Users” template. Inten…
★ 0 · 2025-12-15
PoCs 17
★ 95
Last push 2026-05-02 (5 months, 1 week ago)
Fetching description from NVD…
Show 8 of 17 repositories
TAM-K592/CVE-2024-53677-S2-067
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code …
★ 95 · 2024-12-20
PoCs 8
★ 100
Last push 2026-04-27 (5 months, 1 week ago)
Fetching description from NVD…
Show 8 repositories
PoCs 5
★ 108
Last push 2026-04-25 (5 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
PoCs 5
★ 26
Last push 2026-04-22 (5 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
ac3lives/kyocera-cve-2022-1026
An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords
★ 26 · 2023-03-15
h4po0n/kyocera-cve-2022-1026_SOAP1.1
An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords.
★ 2 · 2025-12-23
r0lh/kygocera
Improved Golang Version of Rapid7 PoC for CVE-2022-1026
★ 0 · 2024-06-13
PoCs 7
★ 46
Last push 2026-04-19 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
MartinFabianIonut/CVE-2025-55315
Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests …
★ 1 · 2025-11-30
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.