Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2024-0670
FRESH PoCMULTI PoC
PoCs 7 ★ 4 Last push 2026-10-09 (22 hours, 14 minutes ago)

Fetching description from NVD…

Show 7 repositories
elsevar11/CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit

This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for Windows. The vu…

★ 4 · 2025-11-16
magicrc/CVE-2024-0670

PoC for CVE-2024-0670

★ 2 · 2025-11-16
tralsesec/CVE-2024-0670

CheckMK Agent Local Privilege Escalation (PoC)

★ 1 · 2026-01-13
zhulin837/checkmk_cve-2024-0670
★ 0 · 2025-11-15
Nikopmpm/Fsociety-CVE-2024-0670-CheckMK-LPE

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

★ 0 · 2026-10-09
Nikopmpm/nikopmpm.github.io

🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.

★ 0 · 2026-01-09
CVE-2018-10933
FRESH PoCHOTMULTI PoC
PoCs 38 ★ 496 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 38 repositories
blacknbunny/CVE-2018-10933

Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)

★ 496 · 2023-12-19
jobroche/libssh-scanner

Script to identify hosts vulnerable to CVE-2018-10933

★ 235 · 2018-11-04
SoledaD208/CVE-2018-10933

CVE-2018-10933 very simple POC

★ 126 · 2018-10-23
hackerhouse-opensource/cve-2018-10933

cve-2018-10933 libssh authentication bypass

★ 110 · 2026-02-02
jas502n/CVE-2018-10933

libssh CVE-2018-10933

★ 22 · 2018-10-20
kn6869610/CVE-2018-10933

Leveraging it is a simple matter of presenting the server with the SSH2_MSG_USERAUTH_SUCCESS message, which shows that the login already occurred without a pr…

★ 14 · 2018-10-17
Virgula0/POC-CVE-2018-10933

LibSSH Authentication Bypass Exploit using RCE

★ 11 · 2018-10-25
marco-lancini/hunt-for-cve-2018-10933

Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)

★ 10 · 2018-10-18
CVE-2019-7609
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 165 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
LandGrey/CVE-2019-7609

exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts

★ 165 · 2023-08-29
jas502n/kibana-RCE

kibana < 6.6.0 未授权远程代码命令执行 (Need Timelion And Canvas),CVE-2019-7609

★ 89 · 2019-10-22
mpgn/CVE-2019-7609

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

★ 56 · 2019-12-20
hekadan/CVE-2019-7609
★ 20 · 2019-12-01
Cr4ckC4t/cve-2019-7609

Kibana <6.6.0 RCE written in python3

★ 4 · 2022-03-17
rhbb/CVE-2019-7609
★ 1 · 2020-04-03
dnr6419/CVE-2019-7609

Kibana Prototype Pollution

★ 1 · 2021-08-25
Akshay15-png/CVE-2019-7609

Exploit for CVE-2019-7609 in python

★ 1 · 2024-07-30
CVE-2023-23752
FRESH PoCMULTI PoC
PoCs 48 ★ 95 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 48 repositories
Acceis/exploit-CVE-2023-23752

Joomla! < 4.2.8 - Unauthenticated information disclosure

★ 95 · 2023-12-27
Ap0dexMe0/CVE-2023-23752

Perform With Mass Exploiter In Joomla 4.2.8.

★ 37 · 2023-07-24
z3n70/CVE-2023-23752

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

★ 18 · 2023-02-24
keyuan15/CVE-2023-23752

Joomla 未授权访问漏洞 CVE-2023-23752

★ 13 · 2023-03-03
gibran-abdillah/CVE-2023-23752

Bulk scanner + get config from CVE-2023-23752

★ 8 · 2023-03-14
adhikara13/CVE-2023-23752

Poc for CVE-2023-23752

★ 8 · 2023-04-04
Youns92/Joomla-v4.2.8---CVE-2023-23752

CVE-2023-23752

★ 7 · 2023-11-28
0xNahim/CVE-2023-23752
★ 6 · 2023-03-26
CVE-2024-23897
FRESH PoCHOTMULTI PoC
PoCs 48 ★ 209 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 48 repositories
h4x0r-dz/CVE-2024-23897

CVE-2024-23897

★ 209 · 2024-01-28
binganao/CVE-2024-23897
★ 101 · 2024-02-01
wjlin0/CVE-2024-23897

CVE-2024-23897 - Jenkins 任意文件读取 利用工具

★ 86 · 2024-03-16
xaitax/CVE-2024-23897

CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.

★ 81 · 2024-02-29
godylockz/CVE-2024-23897

Proof of concept for CVE-2024-23897: Jenkins arbitrary file read

★ 46 · 2026-09-24
kaanatmacaa/CVE-2024-23897

Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)

★ 23 · 2024-02-05
Vozec/CVE-2024-23897

This repository presents a proof-of-concept of CVE-2024-23897

★ 18 · 2024-04-16
P4x1s/CVE-2024-23897

CVE-2024-23897 jenkins-cli

★ 15 · 2024-01-27
CVE-2017-12149
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 208 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
yunxu1/jboss-_CVE-2017-12149

CVE-2017-12149 jboss反序列化 可回显

★ 208 · 2019-03-13
sevck/CVE-2017-12149

CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)

★ 22 · 2017-11-22
1337g/CVE-2017-12149

CVE-2017-12149 JBOSS RCE (TESTED)

★ 15 · 2017-12-23
jreppiks/CVE-2017-12149

Jboss Java Deserialization RCE (CVE-2017-12149)

★ 14 · 2019-08-22
Xcatolin/jboss-deserialization

JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.

★ 0 · 2021-08-04
VVeakee/CVE-2017-12149
★ 0 · 2022-04-16
MrE-Fog/jboss-_CVE-2017-12149
★ 0 · 2023-08-06
JesseClarkND/CVE-2017-12149

Update of https://github.com/1337g/CVE-2017-12149 to work with python3

★ 0 · 2024-04-30
CVE-2022-44268
FRESH PoCHOTMULTI PoC
PoCs 30 ★ 275 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 30 repositories
duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator

★ 275 · 2023-02-02
voidz0r/CVE-2022-44268

A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read

★ 219 · 2025-03-24
Sybil-Scan/imagemagick-lfi-poc

ImageMagick LFI PoC [CVE-2022-44268]

★ 53 · 2023-11-06
kljunowsky/CVE-2022-44268

CVE-2022-44268 ImageMagick Arbitrary File Read - Proof of Concept exploit

★ 26 · 2023-12-29
entr0pie/CVE-2022-44268

PoC of Imagemagick's Arbitrary File Read

★ 13 · 2023-07-03
y1nglamore/CVE-2022-44268-ImageMagick-Vulnerable-Docker-Environment

The vulnerable recurrence docker environment for CVE-2022-44268

★ 10 · 2023-02-03
Vulnmachines/imagemagick-CVE-2022-44268

Imagemagick CVE-2022-44268

★ 8 · 2023-02-06
jnschaeffer/cve-2022-44268-detector

Detect images that likely exploit CVE-2022-44268

★ 5 · 2023-12-06
CVE-2016-3714
FRESH PoCMULTI PoC
PoCs 7 ★ 70 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 7 repositories
Hood3dRob1n/CVE-2016-3714

ImaegMagick Code Execution (CVE-2016-3714)

★ 70 · 2016-05-07
chusiang/CVE-2016-3714.ansible.role

Fix ImageMagick Command Injection (CVE-2016-3714) with Ansible.

★ 1 · 2016-05-11
JoshMorrison99/CVE-2016-3714
★ 1 · 2022-12-02
jackdpeterson/imagick_secure_puppet

a puppet module in response to CVE-2016-3714

★ 0 · 2016-05-04
tommiionfire/CVE-2016-3714
★ 0 · 2016-05-04
CyberCTF/vulhub-imagemagick-cve-2016-3714

Vulhub imagemagick/CVE-2016-3714: ImageTragick on a PHP upload page, run with Isoloom

★ 0 · 2026-10-09
CVE-2025-55182
FRESH PoCHOTMULTI PoC
PoCs 463 ★ 2454 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 463 repositories
assetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

★ 2454 · 2025-12-07
msanft/CVE-2025-55182

Explanation and full RCE PoC for CVE-2025-55182

★ 1431 · 2025-12-08
lachlan2k/React2Shell-CVE-2025-55182-original-poc

Original Proof-of-Concepts for React2Shell CVE-2025-55182

★ 1063 · 2025-12-05
ejpir/CVE-2025-55182-research

CVE-2025-55182 POC

★ 792 · 2025-12-08
mrknow001/RSC_Detector

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

★ 588 · 2025-12-05
emredavut/CVE-2025-55182

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478

★ 313 · 2025-12-06
ynsmroztas/NextRce

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

★ 266 · 2025-12-12
CVE-2021-42013
FRESH PoCMULTI PoC
PoCs 37 ★ 27 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
walnutsecurity/cve-2021-42013

cve-2021-42013.py is a python script that will help in finding Path Traversal or Remote Code Execution vulnerability in Apache 2.4.50

★ 27 · 2023-01-23
Vulnmachines/cve-2021-42013

Apache 2.4.50 Path traversal vulnerability

★ 15 · 2022-08-30
asaotomo/CVE-2021-42013-Apache-RCE-Poc-Exp

Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对 CVE-2021-41773…

★ 10 · 2021-12-24
andrea-mattioli/apache-exploit-CVE-2021-42013

Exploit with integrated shodan search

★ 9 · 2021-10-08
TheLastVvV/CVE-2021-42013_Reverse-Shell

PoC CVE-2021-42013 reverse shell Apache 2.4.50 with CGI

★ 7 · 2021-10-24
BassoNicolas/CVE-2021-42013

CVE-2021-42013 Vulnerability Scanner This Python script checks for the Remote Code Execution (RCE) vulnerability (CVE-2021-42013) in Apache 2.4.50.

★ 3 · 2024-04-07
twseptian/cve-2021-42013-docker-lab

Docker container lab to play/learn with CVE-2021-42013

★ 2 · 2022-02-09
TheLastVvV/CVE-2021-42013

Poc CVE-2021-42013 - Apache 2.4.50 without CGI

★ 2 · 2021-10-23
CVE-2021-41773
FRESH PoCHOTMULTI PoC
PoCs 172 ★ 212 Last push 2026-10-09 (22 hours, 15 minutes ago)

Fetching description from NVD…

Show 8 of 172 repositories
blasty/CVE-2021-41773

CVE-2021-41773 playground

★ 212 · 2021-10-07
inbug-team/CVE-2021-41773_CVE-2021-42013

CVE-2021-41773 CVE-2021-42013漏洞批量检测工具

★ 147 · 2021-10-09
thehackersbrain/CVE-2021-41773

Apache2 2.4.49 - LFI & RCE Exploit - CVE-2021-41773

★ 114 · 2022-03-12
HightechSec/scarce-apache2

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

★ 62 · 2021-10-07
MrCl0wnLab/SimplesApachePathTraversal

Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519

★ 61 · 2024-08-14
iilegacyyii/PoC-CVE-2021-41773
★ 52 · 2021-11-24
lorddemon/CVE-2021-41773-PoC
★ 39 · 2021-10-06
Vulnmachines/cve-2021-41773

CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.

★ 38 · 2022-08-30
CVE-2021-43798
FRESH PoCHOTMULTI PoC
PoCs 60 ★ 369 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 8 of 60 repositories
jas502n/Grafana-CVE-2021-43798

Grafana Unauthorized arbitrary file reading vulnerability

★ 369 · 2023-02-14
A-D-Team/grafanaExp

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source …

★ 269 · 2025-10-17
pedrohavay/exploit-grafana-CVE-2021-43798

This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).

★ 46 · 2021-12-11
taythebot/CVE-2021-43798

CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)

★ 43 · 2021-12-07
zer0yu/CVE-2021-43798

Grafana Arbitrary File Reading Vulnerability

★ 27 · 2021-12-07
Mr-xn/CVE-2021-43798

CVE-2021-43798:Grafana 任意文件读取漏洞

★ 24 · 2021-12-07
MoCh3n/CVE-2021-43798-grafana_fileread

grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL

★ 17 · 2022-01-27
ScorpionsMAX/CVE-2021-43798-Grafana-POC

CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数

★ 14 · 2021-12-17
CVE-2021-22205
FRESH PoCHOTMULTI PoC
PoCs 26 ★ 287 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 8 of 26 repositories
Al1ex/CVE-2021-22205

CVE-2021-22205& GitLab CE/EE RCE

★ 287 · 2022-11-16
inspiringz/CVE-2021-22205

GitLab CE/EE Preauth RCE using ExifTool

★ 238 · 2022-01-16
mr-r3bot/Gitlab-CVE-2021-22205
★ 181 · 2021-11-02
XTeam-Wing/CVE-2021-22205

Pocsuite3 For CVE-2021-22205

★ 86 · 2021-10-28
r0eXpeR/CVE-2021-22205

CVE-2021-22205 Unauthorized RCE

★ 69 · 2021-10-28
whwlsfb/CVE-2021-22205

CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用

★ 23 · 2021-10-30
c0okB/CVE-2021-22205

CVE-2021-22205 RCE

★ 13 · 2022-07-04
keven1z/CVE-2021-22205

CVE-2021-22205 检测脚本,支持getshell和命令执行

★ 12 · 2022-07-25
CVE-2018-16509
FRESH PoCMULTI PoC
PoCs 5 ★ 62 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 5 repositories
farisv/PIL-RCE-Ghostscript-CVE-2018-16509

PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509

★ 62 · 2021-01-06
knqyf263/CVE-2018-16509

CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)

★ 3 · 2019-02-01
rhpco/CVE-2018-16509

CVE-2018-16509 Docker Playground - Ghostscript command execution

★ 1 · 2022-11-07
cved-sources/cve-2018-16509

cve-2018-16509

★ 0 · 2021-04-15
CyberCTF/vulhub-ghostscript-cve-2018-16509

Vulhub ghostscript/CVE-2018-16509: Ghostscript -dSAFER Sandbox Bypass (CVE-2018-16509), run with Isoloom

★ 0 · 2026-10-09
CVE-2020-17519
FRESH PoCMULTI PoC
PoCs 14 ★ 61 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 8 of 14 repositories
MrCl0wnLab/SimplesApachePathTraversal

Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519

★ 61 · 2024-08-14
B1anda0/CVE-2020-17519

Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)

★ 47 · 2021-01-06
murataydemir/CVE-2020-17519

[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read

★ 8 · 2021-01-10
dolevf/apache-flink-directory-traversal.nse

Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script

★ 3 · 2021-01-06
QmF0c3UK/CVE-2020-17519
★ 1 · 2021-01-06
yaunsky/CVE-2020-17519-Apache-Flink

CVE-2020-17519; Apache Flink 任意文件读取; 批量检测

★ 1 · 2021-01-18
givemefivw/CVE-2020-17519

CVE-2020-17519 Cheetah

★ 1 · 2021-04-17
dev-team-12x/CVE-2020-17519

CVE-2020-17519

★ 0 · 2025-07-19
CVE-2015-1427
FRESH PoCMULTI PoC
PoCs 6 ★ 32 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 6 repositories
t0kx/exploit-CVE-2015-1427

Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container

★ 32 · 2018-04-07
cved-sources/cve-2015-1427

cve-2015-1427

★ 0 · 2021-04-15
xpgdgit/CVE-2015-1427
★ 0 · 2022-08-01
Sebikea/CVE-2015-1427-for-trixie

To test elasticsearch vulnerabillity on newer version of debian

★ 0 · 2024-11-10
CyberCTF/vulhub-elasticsearch-cve-2015-1427

Vulhub elasticsearch/CVE-2015-1427: Elasticsearch 1.4.2 Groovy sandbox escape, run with Isoloom

★ 0 · 2026-10-09
CVE-2014-3120
FRESH PoCMULTI PoC
PoCs 5 ★ 6 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 5 repositories
echohtp/ElasticSearch-CVE-2014-3120

POC Code to exploite CVE-2014-3120

★ 6 · 2014-07-07
jeffgeiger/es_inject

Demonstration of CVE-2014-3120

★ 0 · 2014-05-13
xpgdgit/CVE-2014-3120
★ 0 · 2022-08-01
Dungsocool/CVE-2014-3120
★ 0 · 2026-05-31
CyberCTF/vulhub-elasticsearch-cve-2014-3120

Vulhub elasticsearch/CVE-2014-3120: Elasticsearch MVEL Dynamic Script RCE (CVE-2014-3120), run with Isoloom

★ 0 · 2026-10-09
CVE-2019-17564
FRESH PoCMULTI PoC
PoCs 7 ★ 16 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 7 repositories
Dor-Tumarkin/CVE-2019-17564-FastJson-Gadget

Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at https://w…

★ 16 · 2022-12-10
fairyming/CVE-2019-17564

CVE-2019-17564:Apache Dubbo反序列化漏洞

★ 8 · 2020-02-24
Jaky5155/CVE-2019-17564

CVE-2019-17564 Apache Dubbo deserialization RCE

★ 2 · 2020-02-13
Hu3sky/CVE-2019-17564

CVE-2019-17564 : Apache Dubbo Deserialization Remote Code Execution

★ 1 · 2020-02-14
r00t4dm/CVE-2019-17564
★ 0 · 2020-02-12
Exploit-3389/CVE-2019-17564
★ 0 · 2020-02-17
CyberCTF/vulhub-dubbo-cve-2019-17564

Vulhub dubbo/CVE-2019-17564: Apache Dubbo HTTP Protocol Deserialization (CVE-2019-17564), run with Isoloom

★ 0 · 2026-10-09
CVE-2018-7600
FRESH PoCHOTMULTI PoC
PoCs 55 ★ 600 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 8 of 55 repositories
dreadlocked/Drupalgeddon2

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

★ 600 · 2021-01-08
a2u/CVE-2018-7600

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

★ 353 · 2019-03-29
pimps/CVE-2018-7600

Exploit for Drupal 7 <= 7.57 CVE-2018-7600

★ 141 · 2018-04-26
g0rx/CVE-2018-7600-Drupal-RCE

CVE-2018-7600 Drupal RCE

★ 113 · 2018-04-18
firefart/CVE-2018-7600

CVE-2018-7600 - Drupal 7.x RCE

★ 71 · 2018-04-18
lorddemon/drupalgeddon2

Exploit for CVE-2018-7600.. called drupalgeddon2,

★ 11 · 2018-04-19
r3dxpl0it/CVE-2018-7600

CVE-2018-7600 POC (Drupal RCE)

★ 9 · 2020-08-31
zhzyker/CVE-2018-7600-Drupal-POC-EXP

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

★ 8 · 2020-04-07
CVE-2014-3704
FRESH PoCMULTI PoC
PoCs 7 ★ 3 Last push 2026-10-09 (22 hours, 16 minutes ago)

Fetching description from NVD…

Show 7 repositories
Neldeborg/Drupalgeddon-Python3

An rewritten POC on the CVE-2014-3704

★ 3 · 2025-01-06
happynote3966/CVE-2014-3704
★ 1 · 2018-07-17
joaomorenorf/CVE-2014-3704

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for M…

★ 1 · 2025-02-02
AleDiBen/Drupalgeddon

CVE-2014-3704 aka Drupalgeddon - Form-Cache Injection Method

★ 0 · 2022-10-18
fbm31/Audit-BlackBox-Web-to-Root

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade ver…

★ 0 · 2025-12-31
adfortunato/metasploitable3-pentest-writeup

Full home-lab penetration test of Rapid7's Metasploitable3 (Ubuntu 14.04) from Parrot OS. Covers recon, Drupalgeddon (CVE-2014-3704) RCE, SSH credential reuse,…

★ 0 · 2026-09-13
CyberCTF/vulhub-drupal-cve-2014-3704

Vulhub drupal/CVE-2014-3704: Drupal 7.31 Drupalgeddon SQL Injection (CVE-2014-3704), run with Isoloom

★ 0 · 2026-10-09
CVE-2022-34265
FRESH PoCHOTMULTI PoC
PoCs 5 ★ 124 Last push 2026-10-09 (22 hours, 17 minutes ago)

Fetching description from NVD…

Show 5 repositories
aeyesec/CVE-2022-34265

PoC for CVE-2022-34265 (Django)

★ 124 · 2022-07-30
ZhaoQi99/CVE-2022-34265

PoC for CVE-2022-34265

★ 4 · 2022-08-26
traumatising/CVE-2022-34265

CVE-2022-34265 Vulnerability

★ 3 · 2022-07-13
CyberCTF/vulhub-django-cve-2022-34265

Vulhub django/CVE-2022-34265: Django Trunc and Extract SQL Injection (CVE-2022-34265), run with Isoloom

★ 0 · 2026-10-09
CVE-2017-12635
FRESH PoCMULTI PoC
PoCs 5 ★ 10 Last push 2026-10-09 (22 hours, 17 minutes ago)

Fetching description from NVD…

Show 5 repositories
assalielmehdi/CVE-2017-12635

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

★ 10 · 2019-12-15
Dungsocool/CVE-2017-12635_36
★ 0 · 2026-05-29
Darabium/couchdb-exploit

This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Pr…

★ 0 · 2026-09-19
CyberCTF/vulhub-couchdb-cve-2017-12635

Vulhub couchdb/CVE-2017-12635: Apache CouchDB Privilege Escalation (CVE-2017-12635), run with Isoloom

★ 0 · 2026-10-09
CVE-2022-46169
FRESH PoCMULTI PoC
PoCs 37 ★ 47 Last push 2026-10-09 (22 hours, 17 minutes ago)

Fetching description from NVD…

Show 8 of 37 repositories
0xf4n9x/CVE-2022-46169

CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.

★ 47 · 2022-12-08
FredBrave/CVE-2022-46169-CACTI-1.2.22

This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.

★ 42 · 2023-09-11
sAsPeCt488/CVE-2022-46169

PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22

★ 29 · 2023-05-05
ariyaadinatha/cacti-cve-2022-46169-exploit

This is poc of CVE-2022-46169 authentication bypass and remote code execution

★ 15 · 2023-05-18
c3rrberu5/CVE-2022-46169

Exploit to CVE-2022-46169 vulnerability

★ 9 · 2023-01-16
sh4den/CVE-2022-46169

Cacti Unauthenticated Command Injection

★ 3 · 2026-07-06
N1arut/CVE-2022-46169_POC

RCE POC for CVE-2022-46169

★ 3 · 2023-01-17
icebreack/CVE-2022-46169

Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)

★ 3 · 2023-04-13
CVE-2014-6271
FRESH PoCHOTMULTI PoC
PoCs 95 ★ 232 Last push 2026-10-09 (22 hours, 17 minutes ago)

Fetching description from NVD…

Show 8 of 95 repositories
opsxcq/exploit-CVE-2014-6271

Shellshock exploit + vulnerable environment

★ 232 · 2023-05-11
scottjpack/shellshock_scanner

Python Scanner for "ShellShock" (CVE-2014-6271)

★ 46 · 2014-09-29
hmlio/vaas-cve-2014-6271

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

★ 22 · 2019-10-08
b4keSn4ke/CVE-2014-6271

Shellshock exploit aka CVE-2014-6271

★ 15 · 2022-04-01
cj1324/CGIShell

shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI

★ 13 · 2014-10-02
francisck/shellshock-cgi

A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server

★ 12 · 2015-06-19
indiandragon/Shellshock-Vulnerability-Scan

Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock

★ 11 · 2021-08-31
npm/ansible-bashpocalypse

Patch for CVE-2014-6271

★ 6 · 2014-09-24
CVE-2021-25646
FRESH PoCHOTMULTI PoC
PoCs 13 ★ 1073 Last push 2026-10-09 (22 hours, 17 minutes ago)

Fetching description from NVD…

Show 8 of 13 repositories
1n7erface/PocList

Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…

★ 1073 · 2023-05-11
yaunsky/cve-2021-25646

Apache Druid 远程代码执行;检测脚本

★ 17 · 2021-02-03
j2ekim/CVE-2021-25646

Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646

★ 4 · 2021-12-12
k7pro/CVE-2021-25646-exp

CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具

★ 4 · 2025-02-18
givemefivw/CVE-2021-25646

CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本

★ 3 · 2021-04-15
lp008/CVE-2021-25646
★ 2 · 2021-02-03
Ormicron/CVE-2021-25646-GUI

CSharp CVE-2021-25646-GUI

★ 1 · 2021-02-05
< Prev Page 3 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.