Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
14New in 24h
366PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2018-0802
HOTMULTI PoC
PoCs 6 ★ 270 Last push 2023-03-06 (3 years, 7 months ago)

Fetching description from NVD…

Show 6 repositories
rxwx/CVE-2018-0802

PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)

★ 270 · 2018-02-28
Ridter/RTF_11882_0802

PoC for CVE-2018-0802 And CVE-2017-11882

★ 166 · 2018-01-12
zldww2011/CVE-2018-0802_POC

Exploit the vulnerability to execute the calculator

★ 67 · 2018-01-11
Abdibimantara/Maldoc-Analysis

Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal deng…

★ 1 · 2023-03-06
roninAPT/CVE-2018-0802
★ 0 · 2021-02-20
CVE-2020-8165
MULTI PoC
PoCs 7 ★ 42 Last push 2023-01-19 (3 years, 8 months ago)

Fetching description from NVD…

Show 7 repositories
masahiro331/CVE-2020-8165
★ 42 · 2023-01-19
hybryx/CVE-2020-8165
★ 4 · 2021-01-03
danielklim/cve-2020-8165-demo
★ 1 · 2021-02-16
taipansec/CVE-2020-8165
★ 0 · 2020-12-25
AssassinUKG/CVE-2020-8165
★ 0 · 2021-01-15
progfay/CVE-2020-8165

PoC for CVE-2020-8165

★ 0 · 2021-01-21
CVE-2020-2555
HOTMULTI PoC
PoCs 5 ★ 177 Last push 2022-12-15 (3 years, 9 months ago)

Fetching description from NVD…

Show 5 repositories
Y4er/CVE-2020-2555

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE

★ 177 · 2022-12-15
wsfengfan/CVE-2020-2555

CVE-2020-2555 Python POC

★ 45 · 2020-04-16
Maskhe/cve-2020-2555

CVE-2020-2555

★ 14 · 2020-03-10
Hu3sky/CVE-2020-2555
★ 3 · 2020-03-06
Qynklee/POC_CVE-2020-2555

poc for CVE-2020-2555

★ 1 · 2021-11-15
CVE-2022-1292
MULTI PoC
PoCs 5 ★ 28 Last push 2022-12-09 (3 years, 10 months ago)

Fetching description from NVD…

Show 5 repositories
alcaparra/CVE-2022-1292

CVE-2022-1292 OpenSSL c_rehash Vulnerability - POC

★ 28 · 2022-07-20
und3sc0n0c1d0/CVE-2022-1292

Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system.

★ 7 · 2022-12-09
greek0x0/CVE-2022-1292

OpenSSL

★ 6 · 2022-09-01
rama291041610/CVE-2022-1292

CVE-2022-1292 OpenSSL c_rehash Vulnerability

★ 5 · 2022-05-30
li8u99/CVE-2022-1292

CVE-2022-1292

★ 4 · 2022-05-24
CVE-2022-3602
HOTMULTI PoC
PoCs 8 ★ 528 Last push 2022-11-24 (3 years, 10 months ago)

Fetching description from NVD…

Show 8 repositories
NCSC-NL/OpenSSL-2022

Operational information regarding CVE-2022-3602 and CVE-2022-3786, two vulnerabilities in OpenSSL 3

★ 528 · 2022-11-18
colmmacc/CVE-2022-3602
★ 169 · 2022-11-01
eatscrayon/CVE-2022-3602-poc
★ 13 · 2022-11-01
corelight/CVE-2022-3602

Detects attempts at exploitation of CVE-2022-3602, a remote code execution vulnerability in OpenSSL v 3.0.0 through v.3.0.6

★ 4 · 2022-11-24
attilaszia/cve-2022-3602

cve-2022-3602 poc

★ 3 · 2022-11-01
alicangnll/SpookySSL-Scanner

SpookySSL CVE-2022-3602 SSLv3 Scanner for Windows, Linux, macOS

★ 1 · 2022-11-02
CVE-2017-8046
MULTI PoC
PoCs 10 ★ 17 Last push 2022-11-10 (3 years, 11 months ago)

Fetching description from NVD…

Show 8 of 10 repositories
m3ssap0/spring-break_cve-2017-8046

This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).

★ 17 · 2021-06-04
m3ssap0/SpringBreakVulnerableApp

WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!

★ 14 · 2018-10-08
sj/spring-data-rest-CVE-2017-8046

Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)

★ 1 · 2022-05-25
FixYourFace/SpringBreakPoC

PoC for SpringBreak (CVE-2017-8046)

★ 1 · 2018-03-12
jkutner/spring-break-cve-2017-8046

This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).

★ 1 · 2018-04-16
cved-sources/cve-2017-8046

cve-2017-8046

★ 1 · 2021-04-15
bkhablenko/CVE-2017-8046
★ 0 · 2018-09-26
jsotiro/VulnerableSpringDataRest

An intentionally vulnerable (CVE-2017-8046) SrpingData REST appl with Swagger Support for pentesting purposes

★ 0 · 2019-05-08
CVE-2015-7547
HOTMULTI PoC
PoCs 11 ★ 543 Last push 2022-10-29 (3 years, 11 months ago)

Fetching description from NVD…

Show 8 of 11 repositories
fjserna/CVE-2015-7547

Proof of concept for CVE-2015-7547

★ 543 · 2016-02-20
eSentire/cve-2015-7547-public

PoC attack server for CVE-2015-7547 buffer overflow vulnerability in glibc DNS stub resolver (public version)

★ 10 · 2016-04-25
jgajek/cve-2015-7547

PoC exploit server for CVE-2015-7547

★ 8 · 2016-03-30
cakuzo/CVE-2015-7547

test script for CVE-2015-7547

★ 5 · 2016-02-17
t0r0t0r0/CVE-2015-7547
★ 1 · 2016-02-22
rexifiles/rex-sec-glibc

glibc check and update in light of CVE-2015-7547

★ 0 · 2016-02-18
babykillerblack/CVE-2015-7547

glibc getaddrinfo stack-based buffer overflow

★ 0 · 2016-02-21
CVE-2022-24990
MULTI PoC
PoCs 6 ★ 38 Last push 2022-10-17 (3 years, 11 months ago)

Fetching description from NVD…

Show 6 repositories
lishang520/CVE-2022-24990

CVE-2022-24990信息泄露+RCE 一条龙

★ 38 · 2022-03-29
0xf4n9x/CVE-2022-24990

CVE-2022-24990 TerraMaster TOS unauthenticated RCE via PHP Object Instantiation

★ 12 · 2022-04-25
VVeakee/CVE-2022-24990-POC

仅仅是poc,并不是exp

★ 4 · 2022-03-15
ZZ-SOCMAP/CVE-2022-24990

TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990

★ 3 · 2022-04-12
Jaky5155/CVE-2022-24990-TerraMaster-TOS--PHP-

CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令

★ 2 · 2022-03-08
CVE-2021-46422
MULTI PoC
PoCs 13 ★ 3 Last push 2022-10-16 (3 years, 11 months ago)

Fetching description from NVD…

Show 8 of 13 repositories
Awei507/CVE-RCE

CVE-2021-46422漏洞

★ 3 · 2022-10-15
Chocapikk/CVE-2021-46422

Telesquare SDT-CW3B1 1.1.0 - OS Command Injection

★ 2 · 2022-10-16
yyqxi/CVE-2021-46422

CVE-2021-46422poc

★ 2 · 2022-10-16
nobodyatall648/CVE-2021-46422

SDT-CW3B1 1.1.0 - OS Command Injection

★ 1 · 2022-05-24
xanszZZ/SDT_CW3B1_rce

批量检测CVE-2021-46422 RCE漏洞

★ 1 · 2022-10-16
latings/CVE-2021-46422

CVE-2021-46422

★ 1 · 2022-10-16
polerstar/CVE-2021-46422-poc

漏洞检测

★ 1 · 2022-10-16
kailing0220/CVE-2021-46422

Telesquare SDT-CW3B1 1.1.0 版本存在操作系统命令注入漏洞。远程攻击者可利用该漏洞在无需任何身份验证的情况下执行操作系统命令。

★ 1 · 2022-10-16
CVE-2022-34918
HOTMULTI PoC
PoCs 5 ★ 244 Last push 2022-09-15 (4 years ago)

Fetching description from NVD…

Show 5 repositories
randorisec/CVE-2022-34918-LPE-PoC
★ 244 · 2022-09-06
veritas501/CVE-2022-34918

CVE-2022-34918 netfilter nf_tables 本地提权 POC

★ 217 · 2022-09-15
linulinu/CVE-2022-34918
★ 0 · 2022-07-25
CVE-2019-0193
MULTI PoC
PoCs 5 ★ 90 Last push 2022-09-13 (4 years ago)

Fetching description from NVD…

Show 5 repositories
jas502n/CVE-2019-0193

Apache Solr DataImport Handler RCE

★ 90 · 2019-08-12
1135/solr_exploit

Apache Solr远程代码执行漏洞(CVE-2019-0193) Exploit

★ 65 · 2020-07-08
xConsoIe/CVE-2019-0193
★ 7 · 2019-03-18
jaychouzzk/CVE-2019-0193-exp
★ 1 · 2019-09-04
freeFV/ApacheSolrRCE

ApacheSolrRCE(CVE-2019-0193)一键写shell,原理是通过代码执行的java文件流写的马。

★ 0 · 2022-09-13
CVE-2021-2109
MULTI PoC
PoCs 6 ★ 31 Last push 2022-08-30 (4 years, 1 month ago)

Fetching description from NVD…

Show 6 repositories
Al1ex/CVE-2021-2109

CVE-2021-2109 && Weblogic Server RCE via JNDI

★ 31 · 2021-01-22
rabbitsafe/CVE-2021-2109
★ 9 · 2021-01-22
yuaneuro/CVE-2021-2109_poc

weblogic CVE-2021-2109批量验证poc

★ 4 · 2021-05-14
Vulnmachines/oracle-weblogic-CVE-2021-2109

Oracle Weblogic RCE - CVE-2022-2109

★ 3 · 2022-08-30
dinosn/CVE-2021-2109

CVE-2021-2109 basic scanner

★ 0 · 2021-08-09
lnwza0x0a/CVE-2021-2109
★ 0 · 2022-03-29
CVE-2019-12735
MULTI PoC
PoCs 5 ★ 9 Last push 2022-07-26 (4 years, 2 months ago)

Fetching description from NVD…

Show 5 repositories
pcy190/ace-vim-neovim

Vim/Neovim Arbitrary Code Execution via Modelines (CVE-2019-12735)

★ 9 · 2019-06-06
nickylimjj/cve-2019-12735

Docker image that lets me study the exploitation of the VIM exploit

★ 1 · 2021-05-28
datntsec/CVE-2019-12735
★ 0 · 2020-10-27
st9007a/CVE-2019-12735

A demo for cve-2019-12735

★ 0 · 2022-07-26
CVE-2021-22005
HOTMULTI PoC
PoCs 12 ★ 194 Last push 2022-07-08 (4 years, 3 months ago)

Fetching description from NVD…

Show 8 of 12 repositories
shmilylty/cve-2021-22005-exp
★ 194 · 2021-12-22
rwincey/CVE-2021-22005
★ 37 · 2021-09-28
TaroballzChen/CVE-2021-22005-metasploit

the metasploit script(POC/EXP) about CVE-2021-22005 VMware vCenter Server contains an arbitrary file upload vulnerability

★ 22 · 2021-10-02
Jun-5heng/CVE-2021-22005

VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng

★ 21 · 2022-07-08
5gstudent/CVE-2021-22005-

CVE-2021-22005批量验证python脚本

★ 13 · 2021-09-25
1ZRR4H/CVE-2021-22005
★ 8 · 2021-09-23
tiagob0b/CVE-2021-22005
★ 2 · 2021-10-24
CVE-2020-8840
MULTI PoC
PoCs 6 ★ 73 Last push 2022-06-17 (4 years, 3 months ago)

Fetching description from NVD…

Show 6 repositories
jas502n/jackson-CVE-2020-8840

FasterXML/jackson-databind 远程代码执行漏洞

★ 73 · 2020-02-21
fairyming/CVE-2020-8840

CVE-2020-8840:FasterXML/jackson-databind 远程代码执行漏洞

★ 37 · 2020-02-24
Wfzsec/FastJson1.2.62-RCE

来源于jackson-CVE-2020-8840,需要开autotype

★ 16 · 2022-06-17
Veraxy00/CVE-2020-8840

Jackson-databind远程代码执行漏洞(CVE-2020-8840)分析复现环境代码

★ 4 · 2020-12-28
Blyth0He/CVE-2020-8840

jackson jndi injection

★ 1 · 2020-06-05
dpredrag/CVE-2020-8840
★ 1 · 2021-01-26
CVE-2019-9787
MULTI PoC
PoCs 6 ★ 3 Last push 2022-04-30 (4 years, 5 months ago)

Fetching description from NVD…

Show 6 repositories
sijiahi/Wordpress_cve-2019-9787_defense

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

★ 3 · 2021-06-21
rkatogit/cve-2019-9787_csrf_poc
★ 2 · 2019-04-15
PalmTreeForest/CodePath_Week_7-8

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

★ 0 · 2019-08-18
matinciel/Wordpress_CVE-2019-9787

Try to reproduce this issue with Docker

★ 0 · 2020-07-02
dexXxed/CVE-2019-9787

Overview PoC of CSRF CVE-2019-9787 WordPress Version 5.1.1

★ 0 · 2021-06-29
CVE-2021-0326
MULTI PoC
PoCs 5 ★ 21 Last push 2022-04-29 (4 years, 5 months ago)

Fetching description from NVD…

Show 5 repositories
aemmitt-ns/skeleton

Skeleton (but pronounced like Peloton): A Zero-Click RCE exploit for CVE-2021-0326

★ 21 · 2022-03-16
CVE-2018-8174
HOTMULTI PoC
PoCs 9 ★ 167 Last push 2022-04-21 (4 years, 5 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
0x09AL/CVE-2018-8174-msf

CVE-2018-8174 - VBScript memory corruption exploit.

★ 167 · 2018-05-23
Yt1g3r/CVE-2018-8174_EXP

CVE-2018-8174_python

★ 138 · 2022-04-19
piotrflorczyk/cve-2018-8174_analysis

Analysis of VBS exploit CVE-2018-8174

★ 30 · 2018-07-12
ruthlezs/ie11_vbscript_exploit

Exploit Generator for CVE-2018-8174 & CVE-2019-0768 (RCE via VBScript Execution in IE11)

★ 9 · 2019-05-23
SyFi/CVE-2018-8174

MS Word MS WordPad via IE VBS Engine RCE

★ 6 · 2018-06-01
orf53975/Rig-Exploit-for-CVE-2018-8174

Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden ifram…

★ 0 · 2018-06-08
likekabin/CVE-2018-8174-msf
★ 0 · 2018-09-06
CVE-2021-28476
HOTMULTI PoC
PoCs 5 ★ 226 Last push 2022-04-17 (4 years, 5 months ago)

Fetching description from NVD…

Show 5 repositories
0vercl0k/CVE-2021-28476

PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.

★ 226 · 2021-06-01
bluefrostsecurity/CVE-2021-28476
★ 9 · 2021-06-02
australeo/CVE-2021-28476

CVE-2021-28476: Hyper-V vmswitch.sys arbitrary pointer dereference from guest VM

★ 6 · 2022-01-16
LaCeeKa/CVE-2021-28476-tools-env

tools for automate configure Ubuntu 20.04 enviroment for testing CVE-2021-28476.

★ 1 · 2021-08-15
dengyang123x/0vercl0k

PoC for CVE-2021-28476 a guest-to-host "Hyper-V Remote Code Execution Vulnerability" in vmswitch.sys.

★ 1 · 2022-04-17
CVE-2018-1002105
HOTMULTI PoC
PoCs 5 ★ 223 Last push 2022-04-14 (4 years, 5 months ago)

Fetching description from NVD…

Show 5 repositories
evict/poc_CVE-2018-1002105

PoC for CVE-2018-1002105.

★ 223 · 2018-12-21
gravitational/cve-2018-1002105

Test utility for cve-2018-1002105

★ 191 · 2018-12-13
imlzw/Kubernetes-1.12.3-all-auto-install

个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署

★ 4 · 2019-02-26
bgeesaman/cve-2018-1002105

PoC command injection example for cve-2018-1002105 based off https://github.com/gravitational/cve-2018-1002105

★ 1 · 2019-04-30
sh-ubh/CVE-2018-1002105
★ 1 · 2022-04-14
CVE-2021-45105
MULTI PoC
PoCs 7 ★ 13 Last push 2022-04-03 (4 years, 6 months ago)

Fetching description from NVD…

Show 7 repositories
cckuailong/Log4j_dos_CVE-2021-45105

Log4j_dos_CVE-2021-45105

★ 13 · 2021-12-19
iAmSOScArEd/log4j2_dos_exploit

log4j2 dos exploit,CVE-2021-45105 exploit,Denial of Service poc

★ 3 · 2021-12-22
name/log4j-remediation

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

★ 1 · 2021-12-24
pravin-pp/log4j2-CVE-2021-45105
★ 0 · 2021-12-18
tejas-nagchandi/CVE-2021-45105

Replicating CVE-2021-45105

★ 0 · 2021-12-20
aajuvonen/CVE-2021-45105-demo

Example payloads for CVE-2021-45105 low complexity vector

★ 0 · 2022-04-03
CVE-2021-40449
HOTMULTI PoC
PoCs 7 ★ 484 Last push 2022-03-05 (4 years, 7 months ago)

Fetching description from NVD…

Show 7 repositories
ly4k/CallbackHell

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

★ 484 · 2021-11-11
KaLendsi/CVE-2021-40449-Exploit

windows 10 14393 LPE

★ 106 · 2021-10-28
SamuelTulach/voidmap

Using CVE-2021-40449 to manual map kernel mode driver

★ 105 · 2022-03-05
Kristal-g/CVE-2021-40449_poc

Exploit for CVE-2021-40449

★ 54 · 2021-11-07
hakivvi/CVE-2021-40449

LPE exploit for a UAF in Windows (CVE-2021-40449).

★ 47 · 2021-11-05
CppXL/cve-2021-40449-poc
★ 1 · 2021-11-12
CVE-2022-21882
HOTMULTI PoC
PoCs 5 ★ 460 Last push 2022-02-15 (4 years, 7 months ago)

Fetching description from NVD…

Show 5 repositories
KaLendsi/CVE-2022-21882

win32k LPE

★ 460 · 2022-01-27
L4ys/CVE-2022-21882
★ 197 · 2022-02-04
sailay1996/cve-2022-21882-poc

lpe poc for cve-2022-21882

★ 49 · 2022-02-07
David-Honisch/CVE-2022-21882

CVE-2022-21882

★ 8 · 2022-02-01
r1l4-i3pur1l4/CVE-2022-21882
★ 6 · 2022-02-15
CVE-2014-3153
HOTMULTI PoC
PoCs 9 ★ 124 Last push 2022-02-01 (4 years, 8 months ago)

Fetching description from NVD…

Show 8 of 9 repositories
timwr/CVE-2014-3153

CVE-2014-3153 aka towelroot

★ 124 · 2017-04-25
geekben/towelroot

Research of CVE-2014-3153 and its famous exploit towelroot on x86

★ 46 · 2014-10-25
dangtunguyen/TowelRoot

Gain root privilege by exploiting CVE-2014-3153 vulnerability

★ 21 · 2018-09-27
android-rooting-tools/libfutex_exploit

CVE-2014-3153 exploit

★ 19 · 2015-10-07
lieanu/CVE-2014-3153

cve2014-3153 exploit for ubuntu x86

★ 18 · 2015-01-24
elongl/CVE-2014-3153

Exploiting CVE-2014-3153, AKA Towelroot.

★ 13 · 2021-01-16
zerodavinci/CVE-2014-3153-exploit

My exploit for kernel exploitation

★ 5 · 2016-03-08
c3c/CVE-2014-3153

towelroot

★ 0 · 2015-09-04
CVE-2017-0213
MULTI PoC
PoCs 6 ★ 57 Last push 2022-01-29 (4 years, 8 months ago)

Fetching description from NVD…

Show 6 repositories
zcgonvh/CVE-2017-0213

CVE-2017-0213 for command line

★ 57 · 2017-07-01
eonrickity/CVE-2017-0213

Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.

★ 13 · 2018-04-17
jbooz1/CVE-2017-0213

A version of CVE-2017-0213 that I plan to use with an Empire stager

★ 1 · 2018-03-21
shaheemirza/CVE-2017-0213-
★ 0 · 2017-06-07
billa3283/CVE-2017-0213
★ 0 · 2017-10-01
Anonymous-Family/CVE-2017-0213

Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, W…

★ 0 · 2022-01-29
< Prev Page 31 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.