Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
3 contacts in last 24h
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
803 results
PoCs 13
★ 113
Last push 2025-08-17 (1 year, 1 month ago)
Fetching description from NVD…
Show 8 of 13 repositories
vulncheck-oss/fetch-broker-conf
A go-exploit for fetching the RocketMQ broker configuration in order to discover indicators of compromise for CVE-2023-33246
★ 5 · 2024-10-25
PoCs 8
★ 60
Last push 2025-08-12 (1 year, 1 month ago)
Fetching description from NVD…
Show 8 repositories
bibo318/CVE-2023-22518
Lỗ hổng ủy quyền không phù hợp trong Trung tâm dữ liệu Confluence và Máy chủ + bugsBonus 🔥
★ 1 · 2024-01-24
PoCs 5
★ 4
Last push 2025-07-26 (1 year, 2 months ago)
Fetching description from NVD…
Show 5 repositories
9carlo6/CVE-2024-23346
This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).
★ 4 · 2025-03-11
DAVIDAROCA27/CVE-2024-23346-exploit
This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious `CIF` file…
★ 4 · 2025-07-26
PoCs 5
★ 21
Last push 2025-07-26 (1 year, 2 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 11
★ 85
Last push 2025-07-23 (1 year, 2 months ago)
Fetching description from NVD…
Show 8 of 11 repositories
lijiejie/log4j2_vul_local_scanner
Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)
★ 85 · 2021-12-22
mergebase/log4j-samples
Public testing data. Samples of log4j library versions to help log4j scanners / detectors improve their accuracy for detecting CVE-2021-45046 and CVE-2021-442…
★ 14 · 2021-12-30
PoCs 5
★ 192
Last push 2025-07-23 (1 year, 2 months ago)
Fetching description from NVD…
Show 5 repositories
kn0x0x/CVE-2025-32756-POC
Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
★ 192 · 2025-06-13
becrevex/CVE-2025-32756
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
★ 0 · 2025-06-09
PoCs 6
★ 9
Last push 2025-07-22 (1 year, 2 months ago)
Fetching description from NVD…
Show 6 repositories
im-hanzou/fubucker
Automatic Mass Tool for checking vulnerability in CVE-2022-1386 - Fusion Builder < 3.6.2 - Unauthenticated SSRF
★ 6 · 2023-03-08
PoCs 5
★ 34
Last push 2025-07-19 (1 year, 2 months ago)
Fetching description from NVD…
Show 5 repositories
PoCs 5
★ 109
Last push 2025-07-18 (1 year, 2 months ago)
Fetching description from NVD…
Show 5 repositories
scabench/fastjson-tp1fn1
a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used
★ 0 · 2024-01-29
PoCs 6
★ 21
Last push 2025-07-07 (1 year, 3 months ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 681
Last push 2025-06-25 (1 year, 3 months ago)
Fetching description from NVD…
Show 5 repositories
f4T1H21/dirty_sock
Local Privilege Escalation via snapd (CVE-2019-7304) Remastered PoC exploit
★ 1 · 2021-07-28
PoCs 5
★ 12
Last push 2025-06-24 (1 year, 3 months ago)
Fetching description from NVD…
Show 5 repositories
zveriu/CVE-2009-0229-PoC
PoC for CVE-2009-0229 "Print Spooler Read File Vulnerability" LPE AFR (related to CVE-2020-1048)
★ 3 · 2020-05-15
Ken-Abruzzi/CVE-2020-1048
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Prin…
★ 2 · 2020-09-21
PoCs 6
★ 39
Last push 2025-06-17 (1 year, 3 months ago)
Fetching description from NVD…
Show 6 repositories
PoCs 9
★ 8
Last push 2025-06-06 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
Nxploited/CVE-2025-3102
Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
★ 8 · 2025-04-14
rhz0d/CVE-2025-3102
Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
★ 2 · 2025-04-15
SUPRAAA-1337/CVE-2025-3102-exploit
Exploitation of an authorization bypass vulnerability in the SureTriggers plugin for WordPress versions <= 1.0.78, allowing unauthenticated attackers to create…
★ 1 · 2025-04-25
SUPRAAA-1337/CVE-2025-3102
Detects the version of the SureTriggers WordPress plugin from exposed asset URLs and compares it to determine if it's vulnerable (<= 1.0.78).
★ 0 · 2025-04-25
SUPRAAA-1337/CVE-2025-3102_v2
Checks the SureTriggers WordPress plugin's readme.txt file for the Stable tag version. If the version is less than or equal to 1.0.78, it is considered vulnera…
★ 0 · 2025-04-25
PoCs 17
★ 13
Last push 2025-06-05 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 17 repositories
whalebone7/EagleEye
To filter the actual vulnerable URLs from the screenshots, you can use the ee.sh script. Simply run ./ee.sh -f "path/to/index_screenshot.txt" -k "hacked" and t…
★ 7 · 2023-05-01
mdaseem03/cpanel_xss_2023
cpanel_xss_2023 is a simple Python script designed for finding CVE-2023-29489 vulnerability in cpanel.
★ 4 · 2024-01-31
ipk1/CVE-2023-29489.py
a pyhton script to test all results from shodan for cPanel CVE-2023-29489, credits to @assetnote, I just automate
★ 2 · 2023-04-28
PoCs 7
★ 8
Last push 2025-06-04 (1 year, 4 months ago)
Fetching description from NVD…
Show 7 repositories
Pol-Ruiz/PoC-CVE-2019-12840
Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2019-12840 la qual te da un RCE en root
★ 0 · 2024-01-25
PoCs 7
★ 43
Last push 2025-06-02 (1 year, 4 months ago)
Fetching description from NVD…
Show 7 repositories
PoCs 10
★ 43
Last push 2025-05-23 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 5
★ 20
Last push 2025-05-18 (1 year, 4 months ago)
Fetching description from NVD…
Show 5 repositories
zxj-hub/CVE-2024-41713POC
Mitel MiCollab 企业协作平台 任意文件读取漏洞(CVE-2024-41713)由于Mitel MiCollab软件的 NuPoint 统一消息 (NPM) 组件中存在身份验证绕过漏洞,并且输入验证不足,未经身份验证的远程攻击者可利用该漏洞执行路径遍历攻击,成功利用可能导致未授权访问、破坏或删除用户的数据…
★ 0 · 2024-12-21
amanverma-wsu/CVE-2024-41713-Scan
A Python script to detect CVE-2024-41713, a directory traversal vulnerability in Apache HTTP Server, enabling unauthorized access to restricted resources. This…
★ 0 · 2025-01-11
PoCs 9
★ 92
Last push 2025-05-16 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 6
★ 1073
Last push 2025-05-15 (1 year, 4 months ago)
Fetching description from NVD…
Show 6 repositories
1n7erface/PocList
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…
★ 1073 · 2023-05-11
PoCs 12
★ 64
Last push 2025-05-14 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 12 repositories
secpool2000/CVE-2020-17530
Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校A…
★ 1 · 2020-12-09
PoCs 9
★ 2
Last push 2025-05-14 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 9 repositories
dream434/CVE-2017-5487
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listi…
★ 0 · 2025-02-22
PoCs 13
★ 886
Last push 2025-05-12 (1 year, 4 months ago)
Fetching description from NVD…
Show 8 of 13 repositories
zhuowei/MacDirtyCowDemo
Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.
★ 410 · 2022-12-21
PoCs 8
★ 3
Last push 2025-05-10 (1 year, 5 months ago)
Fetching description from NVD…
Show 8 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.