Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
345PoC updated in 7 days
filters
803 results
PoCs 7
★ 82
Last push 2026-04-18 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 6
★ 13
Last push 2026-04-18 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 6
★ 9
Last push 2026-04-16 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
junnythemarksman/CVE-2024-24590
Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded ar…
★ 1 · 2024-06-21
PoCs 22
★ 107
Last push 2026-04-16 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 22 repositories
PoCs 8
★ 236
Last push 2026-04-13 (5 months, 3 weeks ago)
Fetching description from NVD…
Show 8 repositories
PoCs 10
★ 53
Last push 2026-04-12 (5 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
Adel2411/cve-2023-38408
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigati…
★ 5 · 2025-07-16
fazilbaig1/cve_2023_38408_scanner
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When us…
★ 0 · 2024-10-17
PoCs 35
★ 889
Last push 2026-04-11 (5 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 35 repositories
eastmountyxz/CVE-2020-0601-EXP
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!
★ 30 · 2020-02-17
PoCs 11
★ 61
Last push 2026-04-11 (5 months, 4 weeks ago)
Fetching description from NVD…
Show 8 of 11 repositories
CsEnox/CVE-2021-22911
Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1
★ 61 · 2023-06-11
jayngng/CVE-2021-22911
Modifed ver of the original exploit to save some times on password reseting for unprivileged user
★ 0 · 2021-09-19
PoCs 5
★ 15
Last push 2026-04-07 (6 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 24
★ 98
Last push 2026-04-07 (6 months ago)
Fetching description from NVD…
Show 8 of 24 repositories
1w4y/IngressNightmare-RCE-POC
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling cod…
★ 1 · 2025-03-26
PoCs 5
★ 23
Last push 2026-04-03 (6 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
xvalegendary/HVCIPwned
CVE-2024-35250 demonstrates that HVCI is not a defense against data-only kernel exploits. As long as a driver bug provides an arbitrary R/W primitive, token sw…
★ 9 · 2026-04-03
PoCs 6
★ 60
Last push 2026-03-30 (6 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
wqfh/CVE-2024-27348
CVE-2024-27348 Exploitation Toolkit: Complete RCE exploit for Apache Huge-Graph-Server vulnerability.
★ 1 · 2025-12-13
p0et08/CVE-2024-27348
This is a repository for Apache HugeGraph Remote Code Execution vulnerability(CVE-2024-27348))
★ 0 · 2025-02-10
PoCs 13
★ 68
Last push 2026-03-30 (6 months, 1 week ago)
Fetching description from NVD…
Show 8 of 13 repositories
nuts7/CVE-2023-27372
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4…
★ 68 · 2024-10-13
PoCs 13
★ 7
Last push 2026-03-28 (6 months, 1 week ago)
Fetching description from NVD…
Show 8 of 13 repositories
MKIRAHMET/PoC-2023-43208
A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.
★ 3 · 2026-02-24
Criz117/CVE-2023-43208-PoC
Proof‑of‑concept Python script demonstrating CVE‑2023‑43208 in Mirth Connect, allowing version checks and command execution on vulnerable instances.
★ 1 · 2026-03-13
PoCs 14
★ 288
Last push 2026-03-28 (6 months, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
z-bool/Venom-JWT
针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)
★ 288 · 2025-08-12
j4k0m/CVE-2018-0114
Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.
★ 4 · 2021-09-04
fevra-dev/ClaimJumper
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-spec…
★ 1 · 2026-01-16
PoCs 8
★ 189
Last push 2026-03-25 (6 months, 2 weeks ago)
Fetching description from NVD…
Show 8 repositories
KuanKuanQAQ/cve-testing
Reproduce CVE-2022-32250 and CVE-2025-21756 by tampering with modprobe_path and hijacking control flow, respectively.
★ 0 · 2025-07-07
PoCs 14
★ 16
Last push 2026-03-24 (6 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
MichaelVenturella/CVE-2025-6018-6019-PoC
A Proof of Concept for chaining CVE-2025-6018 (PAM/Polkit Active Session Bypass) and CVE-2025-6019 (libblockdev SUID Mount Flaw) to achieve Local Privilege Esc…
★ 16 · 2026-02-09
DesertDemons/CVE-2025-6018-6019
CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition LPE to root
★ 5 · 2026-03-24
PoCs 7
★ 1
Last push 2026-03-23 (6 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
TheMalwareGuardian/CVE-2003-0264
Classic stack-based buffer overflow in SLMail 5.1 showing how early mail servers could be compromised through oversized SMTP and POP3 commands.
★ 1 · 2026-03-23
war4uthor/CVE-2003-0264
CVE-2003-0264 - SLMail 5.5 POP3 'PASS' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
★ 0 · 2018-12-19
PoCs 7
★ 32
Last push 2026-03-23 (6 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 7
★ 411
Last push 2026-03-18 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 20
★ 247
Last push 2026-03-16 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 20 repositories
PoCs 13
★ 121
Last push 2026-03-15 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
notkmhn/CVE-2022-21449-TLS-PoC
CVE-2022-21449 Proof of Concept demonstrating its usage with a client running on a vulnerable Java version and a malicious TLS server
★ 121 · 2026-03-15
thack1/CVE-2022-21449
Zeek script to detect exploitation attempts of CVE-2022-21449 targeting TLS clients
★ 5 · 2022-05-01
fevra-dev/ClaimJumper
Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-spec…
★ 1 · 2026-01-16
PoCs 64
★ 532
Last push 2026-03-15 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 64 repositories
YukaFake/CVE-2024-32002-Reverse-Shell
Este script demuestra cómo explotar la vulnerabilidad CVE-2024-32002 para obtener una reverse shell, proporcionando acceso remoto al sistema afectado. Úselo co…
★ 6 · 2024-05-21
PoCs 8
★ 10
Last push 2026-03-14 (6 months, 3 weeks ago)
Fetching description from NVD…
Show 8 repositories
PoCs 5
★ 316
Last push 2026-03-13 (6 months, 4 weeks ago)
Fetching description from NVD…
Show 5 repositories
1NTheKut/CVE-2019-1003000_RCE-DETECTION
A C# module to detect if a Jenkins server is vulnerable to the RCE vulnerability found in CVE-2019-1003000 (chained with CVE-2018-1000861 for pre-auth RCE)
★ 4 · 2019-05-01
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.