Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
344PoC updated in 7 days
filters
803 results
PoCs 13
★ 28
Last push 2026-03-10 (7 months ago)
Fetching description from NVD…
Show 8 of 13 repositories
safe3s/CVE-2022-21661
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
★ 0 · 2022-11-06
PoCs 14
★ 2
Last push 2026-03-10 (7 months ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 5
★ 30
Last push 2026-03-10 (7 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 7
★ 0
Last push 2026-03-10 (7 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 5
★ 200
Last push 2026-03-04 (7 months ago)
Fetching description from NVD…
Show 5 repositories
CrowTheArchfiend/RTCore64-probe
A tiny cpp program to test reading memory using a vulnerable RTCore64.sys driver/device (CVE-2019-16098). It tries to read a "secret" from its own memory usin…
★ 0 · 2026-03-04
PoCs 12
★ 100
Last push 2026-03-01 (7 months, 1 week ago)
Fetching description from NVD…
Show 8 of 12 repositories
aitorfirm/CVE-2025-25257
Exploiting the CVE-2025-25257 vulnerability in FortiWeb. This repository demonstrates secure pre-authenticated SQL injection.
★ 1 · 2025-07-18
0xgh057r3c0n/CVE-2025-25257
PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain RCE. No l…
★ 1 · 2025-07-15
mrmtwoj/CVE-2025-25257
CVE‑2025‑25257 is a critical pre-authentication SQL injection vulnerability affecting Fortinet FortiWeb’s
★ 1 · 2025-07-19
PoCs 5
★ 6
Last push 2026-02-28 (7 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
abbarhissarh/CVE-2020-29607
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files"…
★ 6 · 2022-06-04
PoCs 14
★ 80
Last push 2026-02-25 (7 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 14 repositories
Chocapikk/CVE-2023-4966
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA vi…
★ 80 · 2023-10-26
PoCs 7
★ 1414
Last push 2026-02-21 (7 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
knightswd/NoPacScan
NoPacScan is a CVE-2021-42287/CVE-2021-42278 Scanner,it scan for more domain controllers than other script
★ 87 · 2022-02-17
PoCs 7
★ 32
Last push 2026-02-18 (7 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 5
★ 9
Last push 2026-02-10 (8 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 5
★ 34
Last push 2026-02-10 (8 months ago)
Fetching description from NVD…
Show 5 repositories
ill-deed/CVE-2025-34085-Multi-target
Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells across la…
★ 34 · 2025-07-13
PoCs 9
★ 18
Last push 2026-02-09 (8 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
thefizzyfish/CVE-2023-50564-pluck
CVE-2023-50564 - An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary c…
★ 4 · 2024-10-03
Mrterrestrial/CVE-2023-50564
This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once uploaded, th…
★ 1 · 2024-10-15
PoCs 11
★ 68
Last push 2026-02-08 (8 months ago)
Fetching description from NVD…
Show 8 of 11 repositories
ztrxwzy/joomla.3.7.0exploit
Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data extraction…
★ 2 · 2026-02-08
PoCs 6
★ 9
Last push 2026-02-07 (8 months ago)
Fetching description from NVD…
Show 6 repositories
Chocapikk/CVE-2024-5084
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
★ 9 · 2024-07-17
KTN1990/CVE-2024-5084
WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
★ 0 · 2024-05-31
PoCs 23
★ 74
Last push 2026-02-06 (8 months ago)
Fetching description from NVD…
Show 8 of 23 repositories
Manh130902/CVE-2023-22527-POC
A critical severity Remote Code Execution (RCE) vulnerability (CVE-2023-22527) was discovered in Confluence Server and Data Center.
★ 22 · 2024-01-23
PoCs 13
★ 360
Last push 2026-02-06 (8 months ago)
Fetching description from NVD…
Show 8 of 13 repositories
BishopFox/pwn-pulse
Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
★ 132 · 2020-01-15
cisagov/check-your-pulse
This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.
★ 28 · 2020-08-19
aqhmal/pulsexploit
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
★ 9 · 2020-04-25
es0/CVE-2019-11510_poc
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
★ 5 · 2019-08-27
PoCs 6
★ 4
Last push 2026-02-04 (8 months ago)
Fetching description from NVD…
Show 6 repositories
PoCs 9
★ 65
Last push 2026-02-04 (8 months, 1 week ago)
Fetching description from NVD…
Show 8 of 9 repositories
Polo35/CVE-2020-0022
CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)
★ 37 · 2021-03-21
themmokhtar/CVE-2020-0022
A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)
★ 22 · 2023-11-21
PoCs 9
★ 22
Last push 2026-02-03 (8 months, 1 week ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 6
★ 7
Last push 2026-02-02 (8 months, 1 week ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 7
Last push 2026-01-30 (8 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
LongWayHomie/CVE-2021-43857
Gerapy prior to version 0.9.8 is vulnerable to remote code execution. This issue is patched in version 0.9.8.
★ 7 · 2022-01-03
ProwlSec/gerapy-cve-2021-43857
Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original Exploit‑DB P…
★ 2 · 2025-07-30
PoCs 5
★ 3
Last push 2026-01-28 (8 months, 1 week ago)
Fetching description from NVD…
Show 5 repositories
PoCs 14
★ 27
Last push 2026-01-27 (8 months, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 7
★ 28
Last push 2026-01-27 (8 months, 1 week ago)
Fetching description from NVD…
Show 7 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.