Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
14New in 24h
366PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2024-4439
MULTI PoC
PoCs 5 ★ 12 Last push 2024-11-21 (1 year, 10 months ago)

Fetching description from NVD…

Show 5 repositories
d0rb/CVE-2024-4439

The provided exploit code leverages a stored Cross-Site Scripting (XSS) vulnerability (CVE-2024-4439) in WordPress Core versions up to 6.5.1.

★ 12 · 2024-05-06
MielPopsssssss/CVE-2024-4439

CVE-2024-4439 PoC

★ 2 · 2024-05-06
xssor-dz/-CVE-2024-4439

WordPress Core < 6.5.2 - Unauthenticated & Authenticated (Contributor+) Stored Cross-Site Scripting via Avatar Block

★ 0 · 2024-05-20
soltanali0/CVE-2024-4439

aa

★ 0 · 2024-10-10
w0r1i0g1ht/CVE-2024-4439

CVE-2024-4439 docker and poc

★ 0 · 2024-11-21
CVE-2024-1071
MULTI PoC
PoCs 7 ★ 25 Last push 2024-11-01 (1 year, 11 months ago)

Fetching description from NVD…

Show 7 repositories
gh-ost00/CVE-2024-1071-SQL-Injection

Proof of concept : CVE-2024-1071: WordPress Vulnerability Exploited

★ 25 · 2024-08-30
gbrsh/CVE-2024-1071

Ultimate Member Unauthorized Database Access / SQLi

★ 8 · 2024-02-27
Trackflaw/CVE-2024-1071-Docker

CVE-2024-1071 with Docker

★ 3 · 2024-03-05
Spid3heX/CVE-2024-1071-PoC-Script

wp/ultimate-member - SQL Injection Vulnerability Exploit Script.

★ 2 · 2024-11-01
Matrexdz/CVE-2024-1071

CVE-2024-1071

★ 1 · 2024-03-18
Matrexdz/CVE-2024-1071-Docker
★ 1 · 2024-03-18
CVE-2021-31166
HOTMULTI PoC
PoCs 11 ★ 823 Last push 2024-10-17 (1 year, 11 months ago)

Fetching description from NVD…

Show 8 of 11 repositories
0vercl0k/CVE-2021-31166

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

★ 823 · 2021-06-12
ZZ-SOCMAP/CVE-2021-31166

Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166

★ 19 · 2021-11-04
corelight/CVE-2021-31166

HTTP Protocol Stack CVE-2021-31166

★ 12 · 2024-10-17
zha0gongz1/CVE-2021-31166

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system …

★ 8 · 2021-05-17
0xmaximus/Home-Demolisher

PoC for CVE-2021-31166 and CVE-2022-21907

★ 8 · 2022-12-08
y0g3sh-99/CVE-2021-31166-Exploit

Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)

★ 7 · 2021-07-03
mauricelambert/CVE-2021-31166

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

★ 6 · 2022-03-16
zecopro/CVE-2021-31166

simple bash script for exploit CVE-2021-31166

★ 5 · 2021-05-19
CVE-2013-5211
MULTI PoC
PoCs 5 ★ 15 Last push 2024-10-16 (1 year, 11 months ago)

Fetching description from NVD…

Show 5 repositories
dani87/ntpscanner

Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.

★ 15 · 2014-09-07
sepehrdaddev/ntpdos

PoC for distributed NTP reflection DoS (CVE-2013-5211)

★ 10 · 2019-10-04
0xhav0c/CVE-2013-5211
★ 6 · 2023-05-03
suedadam/ntpscanner

NTP monlist scanner CVE-2013-5211

★ 2 · 2014-12-14
requiempentest/NTP_CVE-2013-5211

Exploit and check CVE-2013-5211

★ 0 · 2024-10-16
CVE-2022-1015
HOTMULTI PoC
PoCs 9 ★ 209 Last push 2024-10-15 (1 year, 11 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
pqlx/CVE-2022-1015

Local privilege escalation PoC for Linux kernel CVE-2022-1015

★ 209 · 2022-04-03
ysanatomic/CVE-2022-1015

A write-up and LPE PoC of an OOB read and write vulnerability in the Linux Kernel.

★ 4 · 2022-11-12
pivik271/CVE-2022-1015
★ 1 · 2023-03-22
more-kohii/CVE-2022-1015

Linux Kernel 1-Day Analysis & Exploitation

★ 1 · 2023-08-08
zanezhub/CVE-2022-1015-1016

Traducción al español de los CVE-2022-1015 y 1016 descubiertos y documentados por David.

★ 0 · 2022-04-14
wlswotmd/CVE-2022-1015
★ 0 · 2023-04-26
delsploit/CVE-2022-1015
★ 0 · 2023-03-06
0range1337/CVE-2022-1015
★ 0 · 2024-03-18
CVE-2024-29973
MULTI PoC
PoCs 6 ★ 10 Last push 2024-10-11 (1 year, 11 months ago)

Fetching description from NVD…

Show 6 repositories
bigb0x/CVE-2024-29973

POC for CVE-2024-29973

★ 10 · 2024-07-06
NanoWraith/CVE-2024-29973
★ 10 · 2024-06-20
RevoltSecurities/CVE-2024-29973

Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance.

★ 6 · 2024-06-21
momika233/CVE-2024-29973
★ 3 · 2024-06-19
aerchy/CVE-2024-29973
★ 2 · 2024-10-11
p0et08/CVE-2024-29973

PoC and Bulk Scanner for CVE-2024-29973

★ 0 · 2024-06-21
CVE-2020-6287
HOTMULTI PoC
PoCs 7 ★ 223 Last push 2024-10-07 (2 years ago)

Fetching description from NVD…

Show 7 repositories
chipik/SAP_RECON

PoC for CVE-2020-6287, CVE-2020-6286 (SAP RECON vulnerability)

★ 223 · 2020-09-29
duc-nt/CVE-2020-6287-exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR m…

★ 96 · 2020-07-21
murataydemir/CVE-2020-6287

[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)

★ 13 · 2020-09-18
ynsmroztas/CVE-2020-6287-Sap-Add-User

sap netweaver portal add user administrator

★ 1 · 2020-07-22
dylvie/CVE-2020-6287_SAP-NetWeaver-bypass-auth

Automated Exploit for CVE-2020-6287

★ 1 · 2024-10-07
qmakake/SAP_CVE-2020-6287_find_mandate

Checker help to verify created account or find it's mandat

★ 0 · 2023-04-07
CVE-2020-9484
HOTMULTI PoC
PoCs 17 ★ 214 Last push 2024-10-06 (2 years ago)

Fetching description from NVD…

Show 8 of 17 repositories
threedr3am/tomcat-cluster-session-sync-exp

tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞,这个是sessi…

★ 214 · 2020-05-19
masahiro331/CVE-2020-9484
★ 126 · 2021-10-28
IdealDreamLast/CVE-2020-9484

用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞

★ 52 · 2020-05-21
PenTestical/CVE-2020-9484
★ 35 · 2022-04-16
0dayCTF/CVE-2020-9484

Remake of CVE-2020-9484 by Pentestical

★ 26 · 2024-09-16
d3fudd/CVE-2020-9484_Exploit

Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE

★ 17 · 2023-04-17
VICXOR/CVE-2020-9484

POC for CVE-2020-9484

★ 13 · 2021-02-10
anjai94/CVE-2020-9484-exploit
★ 6 · 2020-09-05
CVE-2023-0297
MULTI PoC
PoCs 6 ★ 28 Last push 2024-10-04 (2 years ago)

Fetching description from NVD…

Show 6 repositories
bAuh0lz/CVE-2023-0297_Pre-auth_RCE_in_pyLoad

CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad

★ 28 · 2023-01-14
Small-ears/CVE-2023-0297

poc

★ 2 · 2023-02-17
overgrowncarrot1/CVE-2023-0297
★ 1 · 2023-06-15
hazeyez/CVE-2023-0297

RCE Unauth in PyLoad <0.5.0b3.dev31

★ 0 · 2023-05-21
btar1gan/exploit_CVE-2023-0297

New exploit for pyLoad v0.5.0 - Unauthenticated remote code excecution

★ 0 · 2024-09-15
S4MY9/CVE-2023-0297

RCE in pyload prior to 0.5.0b3.dev31.

★ 0 · 2024-10-04
CVE-2022-26809
HOTMULTI PoC
PoCs 10 ★ 409 Last push 2024-09-16 (2 years ago)

Fetching description from NVD…

Show 8 of 10 repositories
fuckjsonp/FuckJsonp-RCE-CVE-2022-26809-SQL-XSS-FuckJsonp

警惕 一种针对红队的新型溯源手段!

★ 409 · 2022-07-27
s1ckb017/PoC-CVE-2022-26809

PoC for CVE-2022-26809, analisys and considerations are shown in the github.io.

★ 107 · 2022-06-18
yuanLink/CVE-2022-26809
★ 61 · 2022-05-25
corelight/cve-2022-26809

Detects attempts and successful exploitation of CVE-2022-26809

★ 32 · 2024-09-16
websecnl/CVE-2022-26809

Remote Code Execution Exploit in the RPC Library

★ 27 · 2022-04-19
sherlocksecurity/Microsoft-CVE-2022-26809-The-Little-Boy

The poc for CVE-2022-26809 RCE via RPC will be updated here.

★ 19 · 2022-04-18
auduongxuan/CVE-2022-26809
★ 7 · 2022-04-14
Lay0us/CVE-2022-26809-RCE

This repository contains a PoC for remote code execution CVE-2022-26809

★ 0 · 2022-04-21
CVE-2024-4879
MULTI PoC
PoCs 8 ★ 26 Last push 2024-09-13 (2 years ago)

Fetching description from NVD…

Show 8 repositories
Brut-Security/CVE-2024-4879

CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow

★ 26 · 2024-07-13
bigb0x/CVE-2024-4879

Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability

★ 10 · 2024-07-12
NoTsPepino/CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning

CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.

★ 5 · 2024-08-03
Mr-r00t11/CVE-2024-4879

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerabili…

★ 4 · 2024-07-12
gh-ost00/CVE-2024-4879

Jelly Template Injection Vulnerability in ServiceNow | POC CVE-2024-4879

★ 4 · 2024-08-27
GraySignal/CVE-2024-4879-ServiceNow

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

★ 1 · 2024-07-16
jdusane/CVE-2024-4879

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found. This tool…

★ 0 · 2024-08-14
0xWhoami35/CVE-2024-4879
★ 0 · 2024-09-13
CVE-2024-1709
HOTMULTI PoC
PoCs 5 ★ 113 Last push 2024-09-12 (2 years ago)

Fetching description from NVD…

Show 5 repositories
W01fh4cker/ScreenConnect-AuthBypass-RCE

ScreenConnect AuthBypass(cve-2024-1709) --> RCE!!!

★ 113 · 2024-07-16
HussainFathy/CVE-2024-1709

A Scanner for CVE-2024-1709 - ConnectWise SecureConnect Authentication Bypass Vulnerability

★ 3 · 2024-02-26
AhmedMansour93/Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-

Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)

★ 0 · 2024-09-12
CVE-2023-26035
MULTI PoC
PoCs 5 ★ 24 Last push 2024-09-08 (2 years, 1 month ago)

Fetching description from NVD…

Show 5 repositories
rvzsec/CVE-2023-26035

Unauthenticated RCE in ZoneMinder Snapshots - Poc Exploit

★ 24 · 2024-05-07
heapbytes/CVE-2023-26035

POC script for CVE-2023-26035 (zoneminder 1.36.32)

★ 7 · 2024-09-08
Yuma-Tsushima07/CVE-2023-26035

ZoneMinder Snapshots - Unauthenticated

★ 3 · 2023-12-24
0xfalafel/zoneminder_CVE-2023-26035

Exploit for CVE-2023-26035 affecting ZoneMinder < 1.36.33 and < 1.37.33

★ 1 · 2023-12-27
m3m0o/zoneminder-snapshots-rce-poc

This is a script written in Python that allows the exploitation of the Zoneminder's security flaw described in CVE-2023-26035.

★ 0 · 2024-07-07
CVE-2024-28995
MULTI PoC
PoCs 9 ★ 34 Last push 2024-08-24 (2 years, 1 month ago)

Fetching description from NVD…

Show 8 of 9 repositories
Stuub/CVE-2024-28995

CVE-2024-28955 Exploitation PoC

★ 34 · 2024-07-01
bigb0x/CVE-2024-28995

CVE-2024-28995 POC Vulnerability Scanner

★ 14 · 2024-06-15
gotr00t0day/CVE-2024-28995

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

★ 3 · 2024-08-24
ggfzx/CVE-2024-28995
★ 2 · 2024-06-14
0xc4t/CVE-2024-28995

Exploit for CVE-2024-28995

★ 2 · 2024-06-14
GraySignal/CVE-2024-28995-SolarWinds-Serv-U

Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions

★ 1 · 2024-06-26
demoAlitalia/CVE-2024-28995

CVE-2024-28995 PoC

★ 0 · 2024-06-14
CVE-2023-33733
HOTMULTI PoC
PoCs 5 ★ 119 Last push 2024-07-27 (2 years, 2 months ago)

Fetching description from NVD…

Show 5 repositories
c53elyas/CVE-2023-33733

CVE-2023-33733 reportlab RCE

★ 119 · 2023-09-05
L41KAA/CVE-2023-33733-Exploit-PoC
★ 3 · 2024-07-27
onion2203/Lab_Reportlab

This lab was set up to test CVE-2023-33733

★ 1 · 2024-04-24
buiduchoang24/CVE-2023-33733

This project aims at re-analyzing and PoC about CVE-2023-33733. Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF …

★ 1 · 2024-04-24
hoangbui24/CVE-2023-33733

Reportlab Library - Remote Code Execution

★ 0 · 2024-03-15
CVE-2018-17456
MULTI PoC
PoCs 5 ★ 5 Last push 2024-07-22 (2 years, 2 months ago)

Fetching description from NVD…

Show 5 repositories
AnonymKing/CVE-2018-17456

CVE-2018-17456漏洞复现(PoC+Exp)

★ 5 · 2019-06-22
shpik-kr/CVE-2018-17456

1-day

★ 0 · 2018-10-23
matlink/CVE-2018-17456
★ 0 · 2018-11-08
799600966/CVE-2018-17456
★ 0 · 2019-06-06
KKkai0315/CVE-2018-17456

a test repository for CVE-2018-17456's PoC

★ 0 · 2024-07-22
CVE-2015-3864
MULTI PoC
PoCs 5 ★ 17 Last push 2024-07-10 (2 years, 3 months ago)

Fetching description from NVD…

Show 5 repositories
eudemonics/scaredycat

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another Stagefright…

★ 17 · 2015-12-08
pwnaccelerator/stagefright-cve-2015-3864

PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)

★ 3 · 2015-08-18
HenryVHuang/CVE-2015-3864

just some research notes

★ 0 · 2016-03-30
Cmadhushanka/CVE-2015-3864-Exploitation

year 2 semester 1 Systems and Network Programming Assignment

★ 0 · 2024-07-10
CVE-2023-28252
HOTMULTI PoC
PoCs 7 ★ 184 Last push 2024-07-09 (2 years, 3 months ago)

Fetching description from NVD…

Show 7 repositories
fortra/CVE-2023-28252
★ 184 · 2023-07-10
duck-sec/CVE-2023-28252-Compiled-exe

A modification to fortra's CVE-2023-28252 exploit, compiled to exe

★ 57 · 2024-01-24
byt3n33dl3/CLFS

it's a CVE-2023-28252 (Patched), but feel free to use it for check any outdated software or reseach

★ 6 · 2024-07-09
bkstephen/Compiled-PoC-Binary-For-CVE-2023-28252

The repo contains a precompiled binary which can be run on a Windows machine vulnerable to CVE-2023-28252

★ 5 · 2024-01-01
726232111/CVE-2023-28252
★ 0 · 2023-08-02
Danasuley/CVE-2023-28252-

Обнаружение эксплойта CVE-2023-28252

★ 0 · 2023-11-13
Vulmatch/CVE-2023-28252

The TL;DR for the learnings of Windows Vulnerability CVE-2023-28252

★ 0 · 2024-06-16
CVE-2017-1000251
MULTI PoC
PoCs 5 ★ 19 Last push 2024-07-03 (2 years, 3 months ago)

Fetching description from NVD…

Show 5 repositories
hayzamjs/Blueborne-CVE-2017-1000251

Blueborne CVE-2017-1000251 PoC for linux machines

★ 19 · 2023-03-10
sgxgsx/blueborne-CVE-2017-1000251

Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC) BlueBorne - Proof of Concept - Unarmed/Unweaponized - DoS (Crash) only

★ 6 · 2024-07-03
tlatkdgus1/blueborne-CVE-2017-1000251

clone

★ 0 · 2017-09-28
istanescu/CVE-2017-1000251_Exploit

PoC exploit for CVE-2017-1000251 (modified)

★ 0 · 2022-08-15
CVE-2024-34470
MULTI PoC
PoCs 5 ★ 5 Last push 2024-07-02 (2 years, 3 months ago)

Fetching description from NVD…

Show 5 repositories
bigb0x/CVE-2024-34470

POC and bulk scanner for CVE-2024-34470

★ 5 · 2024-06-19
Mr-r00t11/CVE-2024-34470

A critical vulnerability has been found in HSC Mailinspector up to version 5.2.18. This vulnerability affects an unknown functionality of the file /public/load…

★ 4 · 2024-06-20
Cappricio-Securities/CVE-2024-34470

HSC Mailinspector 5.2.17-3 through 5.2.18 - Local File Inclusion

★ 3 · 2024-06-21
th3gokul/CVE-2024-34470

CVE-2024-34470 : An Unauthenticated Path Traversal Vulnerability in HSC Mailinspector

★ 3 · 2024-07-02
osvaldotenorio/CVE-2024-34470
★ 1 · 2024-05-05
CVE-2023-40127
MULTI PoC
PoCs 5 ★ 0 Last push 2024-07-01 (2 years, 3 months ago)

Fetching description from NVD…

Show 5 repositories
Trinadh465/CVE-2023-40127
★ 0 · 2024-04-09
CVE-2020-3187
MULTI PoC
PoCs 5 ★ 1 Last push 2024-06-24 (2 years, 3 months ago)

Fetching description from NVD…

Show 5 repositories
CrackerCat/CVE-2020-3187
★ 1 · 2020-07-28
Cappricio-Securities/CVE-2020-3187

Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal

★ 1 · 2024-06-24
1337in/CVE-2020-3187
★ 0 · 2020-09-10
sunyyer/CVE-2020-3187-Scanlist

Batch scanning site.

★ 0 · 2023-03-14
sujaygr8/CVE-2020-3187
★ 0 · 2021-06-14
CVE-2019-2618
HOTMULTI PoC
PoCs 7 ★ 2076 Last push 2024-06-16 (2 years, 3 months ago)

Fetching description from NVD…

Show 7 repositories
0xn0ne/weblogicScanner

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、C…

★ 2076 · 2023-11-24
dr0op/WeblogicScan

增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持

★ 962 · 2024-06-16
jas502n/cve-2019-2618

Weblogic Upload Vuln(Need username password)-CVE-2019-2618

★ 173 · 2019-04-17
pyn3rd/CVE-2019-2618

Weblogic Unrestricted File Upload

★ 54 · 2019-04-17
wsfengfan/CVE-2019-2618-

CVE-2019-2618-自己编写

★ 1 · 2019-07-17
he1dan/cve-2019-2618

自用验证

★ 1 · 2019-11-05
ianxtianxt/cve-2019-2618

cve-2019-2618 需要用户名密码

★ 0 · 2019-11-19
CVE-2022-30333
MULTI PoC
PoCs 5 ★ 14 Last push 2024-06-10 (2 years, 4 months ago)

Fetching description from NVD…

Show 5 repositories
rbowes-r7/unrar-cve-2022-30333-poc
★ 14 · 2022-07-18
TheL1ghtVn/CVE-2022-30333-PoC
★ 13 · 2022-07-05
aslitsecurity/Zimbra-CVE-2022-30333

Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.

★ 7 · 2022-07-26
RakhithJK/CVE-2022-30333
★ 0 · 2022-07-22
CVE-2018-1335
MULTI PoC
PoCs 5 ★ 14 Last push 2024-06-06 (2 years, 4 months ago)

Fetching description from NVD…

Show 5 repositories
SkyBlueEternal/CVE-2018-1335-EXP-GUI

GUI版 EXP

★ 14 · 2019-03-20
canumay/cve-2018-1335

CENG 325 - Principles of Information Security And Privacy

★ 1 · 2021-01-18
N0b1e6/CVE-2018-1335-Python3
★ 0 · 2020-02-11
siramk/CVE-2018-1335
★ 0 · 2021-03-26
DigitalNinja00/CVE-2018-1335
★ 0 · 2024-06-06
< Prev Page 28 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.