Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
3 contacts in last 24h
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
803 results
PoCs 9
★ 19
Last push 2026-01-24 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
DeathShotXD/CVE-2025-52691-APT-PoC
An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation, persistence, …
★ 5 · 2025-12-30
you-ssef9/CVE-2025-52691
This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs version detec…
★ 1 · 2025-12-30
PoCs 19
★ 20
Last push 2026-01-22 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
Maalfer/CVE-2024-10924-PoC
Bypass del MFA en WordPress con el plugin Really Simple Security instalado entre las versiones 9.0.0 – 9.1.1.1.
★ 7 · 2024-11-27
PoCs 7
★ 205
Last push 2026-01-22 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
jduck/cve-2015-1538-1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
★ 205 · 2015-09-10
Tharana/vulnerability-exploitation
Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution - CVE-2015-1538
★ 3 · 2020-05-12
xsleaksiki/cve
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
★ 0 · 2026-01-22
PoCs 12
★ 164
Last push 2026-01-20 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 7
★ 10
Last push 2026-01-20 (8 months, 2 weeks ago)
Fetching description from NVD…
Show 7 repositories
5ma1l/CVE-2024-25641
This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26
★ 8 · 2024-09-05
PoCs 28
★ 658
Last push 2026-01-19 (8 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 28 repositories
PoCs 19
★ 515
Last push 2026-01-19 (8 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 19 repositories
shack2/javaserializetools
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
★ 515 · 2020-10-01
pimps/CVE-2019-2725
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
★ 52 · 2019-09-26
PoCs 15
★ 48
Last push 2026-01-18 (8 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
j4k0m/CVE-2018-11235
Auto malicious git repository creation to exploit CVE-2018-11235 a Remote Code Execution using Git Sub module.
★ 2 · 2021-09-22
ygouzerh/CVE-2018-11235
Proof of Concept - RCE Exploitation : Git submodules' names vulnerability - Ensimag November 2018
★ 1 · 2019-05-14
PoCs 5
★ 5
Last push 2026-01-17 (8 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
hidesec/CVE-2025-32421
Comprehensive demonstration of CVE-2025-32421 Eclipse technique - a sophisticated race condition attack against Next.js 15.0.4 that bypasses the original CVE-2…
★ 1 · 2025-10-11
PoCs 5
★ 6
Last push 2026-01-09 (9 months ago)
Fetching description from NVD…
Show 5 repositories
0xEval/cve-2015-3224
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python
★ 6 · 2018-05-03
PoCs 10
★ 88
Last push 2026-01-09 (9 months ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 8
★ 58
Last push 2026-01-08 (9 months ago)
Fetching description from NVD…
Show 8 repositories
Chocapikk/CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administr…
★ 58 · 2026-01-08
duy-31/CVE-2023-46805_CVE-2024-21887
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted reso…
★ 23 · 2024-01-17
rxwx/pulse-meter
Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0282.
★ 1 · 2025-02-13
PoCs 21
★ 2076
Last push 2026-01-07 (9 months ago)
Fetching description from NVD…
Show 8 of 21 repositories
0xn0ne/weblogicScanner
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、C…
★ 2076 · 2023-11-24
PoCs 7
★ 4
Last push 2026-01-07 (9 months ago)
Fetching description from NVD…
Show 7 repositories
Mattb709/CVE-2025-29306-PoC-FoxCMS-RCE
Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets, executes comma…
★ 4 · 2025-04-27
amalpvatayam67/day06-foxcms-rce
This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code execution.
★ 0 · 2025-09-18
PoCs 14
★ 258
Last push 2025-12-29 (9 months, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 6
★ 62
Last push 2025-12-27 (9 months, 2 weeks ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 102
Last push 2025-12-24 (9 months, 2 weeks ago)
Fetching description from NVD…
Show 5 repositories
0xf4n9x/CVE-2023-0669
CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrar…
★ 102 · 2024-04-16
Avento/CVE-2023-0669
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
★ 8 · 2023-07-07
PoCs 6
★ 5
Last push 2025-12-19 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
MataKucing-OFC/CVE-2025-13486
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() fun…
★ 2 · 2025-12-05
PoCs 5
★ 62
Last push 2025-12-18 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
Cyberw1ng/CVE-2025-33053-POC
POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on hands-on exploita…
★ 0 · 2025-12-18
PoCs 5
★ 70
Last push 2025-12-17 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 5 repositories
PoCs 10
★ 463
Last push 2025-12-17 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 7
★ 33
Last push 2025-12-15 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 7 repositories
PoCs 6
★ 29
Last push 2025-12-15 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 6 repositories
skimask1690/CVE-2025-6218-POC
Proof of Concept for CVE-2025-6218, demonstrating the exploitation of a vulnerability in WinRAR versions 7.11 and under, involving improper handling of archive…
★ 29 · 2025-07-01
PoCs 8
★ 205
Last push 2025-12-14 (9 months, 3 weeks ago)
Fetching description from NVD…
Show 8 repositories
PoCs 5
★ 4
Last push 2025-12-13 (9 months, 4 weeks ago)
Fetching description from NVD…
Show 5 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.