Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
361PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-64560
FRESH PoCMULTI PoC
PoCs 10 ★ 73 Last push 2026-10-09 (16 hours, 21 minutes ago)

Fetching description from NVD…

Show 8 of 10 repositories
quyicheng03-boop/xiaomi15-dada-cve-2026-64560

Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8

★ 21 · 2026-09-05
a23bc/op13-cve-2026-64560
★ 11 · 2026-09-27
qingle009/opace6-cve-2026-64560

OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

★ 7 · 2026-09-29
imkidz0/CVE-2026-64560-exploit

Exploit of CVE-2026-64560 for kernelCTF, LTS-6.12.95

★ 2 · 2026-10-03
Become-ILLUSORY/cve-2026-64560-a16

CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port

★ 1 · 2026-09-26
Wangs-official/opace6-cve-2026-64560

针对 OnePlus Ace6 设备的 cve-2026-64560 复现

★ 1 · 2026-09-25
CVE-2026-88771
CRITICALFRESH PoCMULTI PoC
CVSS 9.5 CRITICAL CWE-20 Published 2026-09-27 PoCs 12 ★ 23 Last push 2026-10-09 (20 hours, 41 minutes ago)

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Show 8 of 12 repositories
ThomasPoppelgaard/netscaler-ctx697096-checker

Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…

★ 18 · 2026-10-08
technion/netscaler_scanner

Tooling related to CVE-2026-88771 and CVE-2026-88772

★ 1 · 2026-10-09
grupooruss/netscaler-defensive-checker

Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778

★ 1 · 2026-10-08
EXEcution-py/CVE-2026-88771-POC

Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total

★ 0 · 2026-09-28
techupdate24/citrix-netscaler-cve-2026-88771-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-28
SwiftSecur/CVE-2026-88771-HuntScript

A detection/hunting script for compromise related to CVE-2026-88771

★ 0 · 2026-09-29
CVE-2026-41089
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 231 Last push 2026-10-09 (22 hours, 29 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
0xABCD01/CVE-2026-41089

Netlogon and CLDAP vulnerability research with a proof of concept.

★ 231 · 2026-06-02
SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

★ 67 · 2026-09-11
HydraSoft/CVE-2026-41089-Netlogon-RCE

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …

★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…

★ 14 · 2026-06-04
hnytgl/CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

★ 13 · 2026-09-26
0xBlackash/CVE-2026-41089

CVE-2026-41089

★ 11 · 2026-06-05
ZeroDayVPN/CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…

★ 5 · 2026-09-29
opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

★ 1 · 2026-10-08
CVE-2026-45585
FRESH PoCMULTI PoC
PoCs 11 ★ 7 Last push 2026-10-09 (22 hours, 34 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
Desireeontrial76/yellowkey-bitlocker

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

★ 7 · 2026-10-09
andrei-majer/bitlocker-hardening

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

★ 5 · 2026-05-24
YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own.…

★ 3 · 2026-09-27
everest90909/YellowKey-WinRE-Remediation

Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…

★ 1 · 2026-05-21
0xBlackash/CVE-2026-45585

CVE-2026-45585

★ 1 · 2026-05-31
bjbakker1984/Yellowkey-mitigation

A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions

★ 0 · 2026-05-20
ChanderManiPandey2022/Yellow-Key-Check

YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)

★ 0 · 2026-06-04
ChanderManiPandey2022/YellowKey-BitLocker-Bypass-CVE-2026-45585-Detect-Fix-Automatically-via-Microsoft-Intune

YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune

★ 0 · 2026-06-08
CVE-2026-10520
FRESH PoCMULTI PoC
PoCs 8 ★ 13 Last push 2026-10-09 (22 hours, 38 minutes ago)

Fetching description from NVD…

Show 8 repositories
0xBlackash/CVE-2026-10520

CVE-2026-10520

★ 4 · 2026-06-11
HORKimhab/CVE-2026-10520-10523

CVE-2026-10520 and CVE-2026-10523

★ 0 · 2026-06-11
error-inside/CVE-2026-10520

Root-Level RCE via OS Command Injection in Ivanti Sentry

★ 0 · 2026-06-18
gduma-phData/patch-CVE-2026-10520

Patch: OGNL injection (Apache Struts)

★ 0 · 2026-08-24
01xJB/CVE-2026-10520-POC

Exploit for CVE-2026-10520 | Ivanti Sentry - OS Command Injection

★ 0 · 2026-10-09
CVE-2026-23744
FRESH PoCMULTI PoC
PoCs 40 ★ 12 Last push 2026-10-09 (22 hours, 39 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …

★ 12 · 2026-06-14
suljov/CVE-2026-23744-Remote-Code-Execution-POC

MCPJam inspector contains a remote code execution

★ 12 · 2026-03-22
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in version…

★ 6 · 2026-07-14
FrenzisRed/CVE-2026-23744

CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC

★ 4 · 2026-03-23
luiskrnr/exploit-CVE-2026-23744

MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…

★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …

★ 3 · 2026-08-11
InzegoSec/CVE-2026-23744

Exploit to MCPJam Inspector <=1.4.2

★ 1 · 2026-03-25
ctzisme/CVE-2026-23744

PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).

★ 1 · 2026-03-26
CVE-2026-31431
FRESH PoCHOTMULTI PoC
PoCs 325 ★ 4074 Last push 2026-10-09 (22 hours, 40 minutes ago)

Fetching description from NVD…

Show 8 of 325 repositories
theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

★ 4074 · 2026-04-29
tgies/copy-fail-c

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

★ 445 · 2026-07-17
badsectorlabs/copyfail-go

A Go implementation of copyfail (CVE-2026-31431)

★ 360 · 2026-05-01
Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…

★ 191 · 2026-05-07
Sndav/CVE-2026-31431-Advanced-Exploit

CVE-2026-31431 纯文件利用

★ 111 · 2026-04-30
painoob/Copy-Fail-Exploit-CVE-2026-31431

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …

★ 109 · 2026-04-29
sgkdev/page_inject

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

★ 76 · 2026-05-06
Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)

★ 63 · 2026-05-03
CVE-2025-14847
FRESH PoCMULTI PoC
PoCs 40 ★ 35 Last push 2026-10-09 (22 hours, 59 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
Black1hp/mongobleed-scanner

MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool

★ 35 · 2025-12-28
cybertechajju/CVE-2025-14847_Expolit

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…

★ 34 · 2025-12-27
ProbiusOfficial/CVE-2025-14847

poc for CVE-2025-14847

★ 26 · 2025-12-26
onewinner/CVE-2025-14847

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

★ 15 · 2025-12-26
Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

★ 13 · 2026-01-03
codeb0ssx/CVE-2025-14847-PoC

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

★ 4 · 2025-12-29
joshuavanderpoll/CVE-2025-14847

CVE-2025-14847 (MongoBleed)

★ 4 · 2025-12-29
franksec42/mongobleed-exploit-CVE-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

★ 3 · 2026-02-20
CVE-2024-0670
FRESH PoCMULTI PoC
PoCs 7 ★ 4 Last push 2026-10-09 (23 hours ago)

Fetching description from NVD…

Show 7 repositories
elsevar11/CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit

This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for Windows. The vu…

★ 4 · 2025-11-16
magicrc/CVE-2024-0670

PoC for CVE-2024-0670

★ 2 · 2025-11-16
tralsesec/CVE-2024-0670

CheckMK Agent Local Privilege Escalation (PoC)

★ 1 · 2026-01-13
zhulin837/checkmk_cve-2024-0670
★ 0 · 2025-11-15
Nikopmpm/Fsociety-CVE-2024-0670-CheckMK-LPE

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

★ 0 · 2026-10-09
Nikopmpm/nikopmpm.github.io

🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.

★ 0 · 2026-01-09
CVE-2025-55182
FRESH PoCHOTMULTI PoC
PoCs 462 ★ 2453 Last push 2026-10-09 (23 hours, 1 minute ago)

Fetching description from NVD…

Show 8 of 462 repositories
assetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

★ 2453 · 2025-12-07
msanft/CVE-2025-55182

Explanation and full RCE PoC for CVE-2025-55182

★ 1431 · 2025-12-08
lachlan2k/React2Shell-CVE-2025-55182-original-poc

Original Proof-of-Concepts for React2Shell CVE-2025-55182

★ 1063 · 2025-12-05
ejpir/CVE-2025-55182-research

CVE-2025-55182 POC

★ 791 · 2025-12-08
mrknow001/RSC_Detector

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

★ 588 · 2025-12-05
emredavut/CVE-2025-55182

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478

★ 313 · 2025-12-06
ynsmroztas/NextRce

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

★ 266 · 2025-12-12
CVE-2025-26466
FRESH PoCMULTI PoC
PoCs 5 ★ 5 Last push 2026-10-09 (23 hours, 6 minutes ago)

Fetching description from NVD…

Show 5 repositories
rxerium/CVE-2025-26466

The OpenSSH client and server are vulnerable to a pre-authentication DoS attack between versions 9.5p1 to 9.9p1 (inclusive) that causes memory and CPU consump…

★ 5 · 2025-10-14
mrowkoob/CVE-2025-26466-msf

CVE-2025-26466 - SSH Ping DoS Ruby module for Metasploit Framework

★ 1 · 2025-06-23
tpirate/CVE-2025-26466

poc for CVE-2025-26466

★ 0 · 2026-04-02
acidboonrs/cve-2025-26466-openssh-poc

CVE-2025-26466 OpenSSH SSH2_MSG_PING DoS PoC

★ 0 · 2026-07-29
K0n9-log/cve-2025-26466-canvas
★ 0 · 2026-10-09
CVE-2026-59310
FRESH PoCMULTI PoC
PoCs 5 ★ 4 Last push 2026-10-09 (1 day, 5 hours ago)

Fetching description from NVD…

Show 5 repositories
ChinaRan0/CVE-2026-59310-POC

CVE-2026-59310-POC 仅用于自测,请勿用于攻击

★ 4 · 2026-09-25
BiuTrap/CVE-2026-59310

CVE-2026-59310 PoC

★ 2 · 2026-08-19
chu0119/vc-strike

VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only…

★ 1 · 2026-10-03
HORKimhab/CVE-2026-59310

CVE-2026-59310

★ 0 · 2026-08-17
vpxuser/CVE-2026-59310

ChinaRan0/CVE-2026-59310-POC 的优化版本。子命令、一次性 cron、带远端 PTY 的交互 shell。仅限授权测试。

★ 0 · 2026-10-09
CVE-2004-2687
FRESH PoCMULTI PoC
PoCs 7 ★ 2 Last push 2026-10-08 (1 day, 8 hours ago)

Fetching description from NVD…

Show 7 repositories
k4miyo/CVE-2004-2687

CVE-2004-2687 DistCC Daemon Command Execution

★ 1 · 2021-08-28
germarr93/CyberSecurity-Pentest-Lab

CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab

★ 1 · 2026-10-08
nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687

Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.

★ 0 · 2025-12-24
aish19siddiqua-commits/mtechweek_04

Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink…

★ 0 · 2026-08-22
ocfagb/hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-12…

★ 0 · 2026-08-27
CVE-2026-64638
FRESH PoCMULTI PoC
PoCs 26 ★ 56 Last push 2026-10-08 (1 day, 9 hours ago)

Fetching description from NVD…

Show 8 of 26 repositories
Boreas37/CVE-2026-64638-PoC-XSS2Shell-

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

★ 56 · 2026-08-21
imbas007/CVE-2026-64638-POC

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

★ 11 · 2026-08-08
wordsec/XSS2Shell

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

★ 7 · 2026-08-07
renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell

Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na pági…

★ 3 · 2026-08-07
0xlipon/xss2shell

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

★ 3 · 2026-08-09
5yu4n/CVE-2026-64638

CVE-2026-64638

★ 2 · 2026-08-07
HackSpeak/CVE-2026-64638

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing

★ 2 · 2026-08-08
CVE-2026-85706
FRESH PoCMULTI PoC
PoCs 14 ★ 43 Last push 2026-10-08 (1 day, 9 hours ago)

Fetching description from NVD…

Show 8 of 14 repositories
guneykabel/cve-2026-85706

Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1

★ 43 · 2026-09-11
EQSTLab/CVE-2026-85706

GitLab Unauthenticated Arbitrary File Read

★ 26 · 2026-09-28
mhtsec/CVE-2026-85706

GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC

★ 12 · 2026-09-11
ynsmroztas/GitLabSniper

CVE-2026-85706 Unauthenticated File Read

★ 9 · 2026-09-11
0xlyvio/cve-2026-85706-poc-exploit-gitlab

cve-2026-85706-poc-exploit-gitlab

★ 4 · 2026-09-12
FlowerWitch/CVE-2026-85706_docker_exp

CVE-2026-85706_docker_exp

★ 2 · 2026-09-11
jithinkrishnanrs/gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path trav…

★ 2 · 2026-09-13
plur1bu5/gitread

CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

★ 1 · 2026-09-13
CVE-2026-82329
FRESH PoCMULTI PoC
PoCs 8 ★ 12 Last push 2026-10-08 (1 day, 10 hours ago)

Fetching description from NVD…

Show 8 repositories
dinosn/cve-2026-82329-jfrog-artifactory

CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis

★ 12 · 2026-09-01
ynsmroztas/CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

CVE-2026-82329 — JFrog Artifactory (self-hosted) Auth Bypass

★ 6 · 2026-09-02
tc4dy/CVE-2026-82329-PoC-Exploit

CVE-2026-82329 – JFrog Artifactory Auth Bypass Toolkit (CVSS 9.8) | Red/Blue Team suite for self-hosted Artifactory 7.x (111-161). 2 tools: Full Exploit (JWTfo…

★ 3 · 2026-10-08
0xTerror/CVE-2026-82329-JFrog-Artifactory-

CVE-2026-82329 — JFrog Artifactory Auth Bypass

★ 2 · 2026-09-07
realalexandergeorgiev/artifactory-CVE-2026-82329-poc.py

CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)

★ 1 · 2026-09-02
HORKimhab/CVE-2026-82329

CVE-2026-82329 - Draft or TODO

★ 0 · 2026-09-01
0xCyp1337/CVE-2026-82329

CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges.…

★ 0 · 2026-09-03
gagaltotal/CVE-2026-82329-poc

CVE-2026-82329 Poc

★ 0 · 2026-09-04
CVE-2026-42945
FRESH PoCMULTI PoC
PoCs 45 ★ 64 Last push 2026-10-08 (1 day, 15 hours ago)

Fetching description from NVD…

Show 8 of 45 repositories
cipherspy/CVE-2026-42945-POC

exploit for CVE-2026-42945

★ 64 · 2026-05-14
friparia/NGINX_RIFT_SCAN_CVE_2026_42945

Nginx Rewrite CVE Scan(CVE-2026-42945 nginx-rift CVE-2026-9256)

★ 34 · 2026-05-27
MateusVerass/nGixshell

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

★ 26 · 2026-09-26
rheodev/CVE-2026-42945

NGINX Rift 漏洞分析与复现

★ 23 · 2026-05-14
oseasfr/Scanner_CVE_2026-42945

Script Python para detecção de instâncias Nginx vulneráveis ao CVE-2026-42945 em IPs, CIDRs e ASNs.

★ 19 · 2026-05-20
p3Nt3st3r-sTAr/CVE-2026-42945-POC
★ 15 · 2026-05-14
nu0l/NGINX-Rift

CVE-2026-42945 NGINX 堆溢出漏洞扫描与验证工具

★ 5 · 2026-05-26
iammerrida-source/nginx-rift-detect

Behavioral detection script for CVE-2026-42945 (NGINX Rift) — heap overflow in ngx_http_rewrite_module. No RCE, crash-based detection only.

★ 4 · 2026-05-15
CVE-2025-57819
FRESH PoCMULTI PoC
PoCs 25 ★ 30 Last push 2026-10-08 (1 day, 15 hours ago)

Fetching description from NVD…

Show 8 of 25 repositories
0xEhab/FreePBX-CVE-2025-57819-RCE
★ 17 · 2026-06-06
MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819

FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.

★ 8 · 2025-09-12
blueisbeautiful/CVE-2025-57819

FreePBX SQL Injection Exploit

★ 7 · 2025-09-01
b4sh2/CVE-2025-57819-poc

CVE-2025-57819 -> rce

★ 7 · 2026-06-07
cybertechajju/cve-2025-57819

Detects vulnerable FreePBX versions affected by CVE-2025-57819.

★ 6 · 2025-08-30
orange0Mint/CVE-2025-57819_FreePBX

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using…

★ 2 · 2025-09-18
Jeanback1/CVE-2025-57819-exploit

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

★ 2 · 2026-06-07
CVE-2026-46242
FRESH PoCMULTI PoC
PoCs 5 ★ 20 Last push 2026-10-08 (1 day, 15 hours ago)

Fetching description from NVD…

Show 5 repositories
0xBlackash/CVE-2026-46242

CVE-2026-46242

★ 20 · 2026-07-04
Baba01hacker666/CVE-2026-46242

CVE-2026-46242

★ 2 · 2026-07-11
SaithFranklinB/ScannerBadEpoll

Verificador de Vulnerabilidad: Bad Epoll (CVE-2026-46242)

★ 1 · 2026-07-08
BinaryMasc/CVE-2026-46242

aarch64 race condition checker

★ 0 · 2026-08-20
CVE-2025-21479
FRESH PoCHOTMULTI PoC
PoCs 15 ★ 278 Last push 2026-10-08 (1 day, 16 hours ago)

Fetching description from NVD…

Show 8 of 15 repositories
zhuowei/cheese

CVE-2025-21479 proof-of-concept, I think

★ 278 · 2025-08-16
sarabpal-dev/cheese-cake

A proof-of-concept for CVE-2025-21479, chained with a Dirty Pagetable technique.

★ 35 · 2025-12-31
ma4the/omae-wa-cheese-da

CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)

★ 18 · 2026-06-30
CamsShaft/SELinux-Permissive-Only-CVE-2025-21479

This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the adreno kgsl on many devices including Samsung snapd…

★ 8 · 2026-08-14
Qingizi7/cve-2025-21479_iqooneo8

Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

★ 7 · 2026-09-06
linux-tools/VIVO-IQOO-Neo9-Root-Tools

Support OriginOS 4~ OriginOS 6(Some firmware requires manual, individual adaptation), using CVE-2025-21479,CVE-2026-43499

★ 5 · 2026-10-08
RamenFast/zenfone9-root

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

★ 4 · 2026-09-18
CVE-2025-62215
FRESH PoCMULTI PoC
PoCs 7 ★ 21 Last push 2026-10-08 (1 day, 16 hours ago)

Fetching description from NVD…

Show 7 repositories
abrewer251/CVE-2025-62215_Windows_Kernel_PE

This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM. The exploit…

★ 21 · 2025-11-18
gowonisgood/CVE-2025-62215-POC
★ 11 · 2026-05-21
mrk336/Kernel-Chaos-Weaponizing-CVE-2025-62215-for-SYSTEM-Privilege-Escalation

Hands‑on analysis of CVE‑2025‑62215, a Windows Kernel race condition exploited in the wild. Demonstrates privilege escalation to SYSTEM, detection scripts, and…

★ 3 · 2025-11-18
theman001/CVE-2025-62215

CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP

★ 2 · 2025-12-23
nullxall/cve-2025-62215-exploit-poc

CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a z…

★ 1 · 2025-11-14
uky007/CVE-2025-62215_analysis

CVE-2025-62215 exploit development using Claude Code Agent Team

★ 0 · 2026-02-11
Hu2ie/CVE-2025-62215-Windows-Kernel---Elevation-of-Privilege

Windows Kernel - Elevation of Privilege

★ 0 · 2026-10-08
CVE-2026-48908
FRESH PoCMULTI PoC
PoCs 12 ★ 18 Last push 2026-10-08 (1 day, 17 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
papageo75/CVE-2026-48908-PoC

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guard…

★ 18 · 2026-06-23
Jenderal92/CVE-2026-48908

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. Fo…

★ 3 · 2026-07-08
0xBlackash/CVE-2026-48908

CVE-2026-48908

★ 2 · 2026-06-24
imXur/CVE-2026-48908-Joomla-SP-Page-Builder-RCE

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

★ 2 · 2026-07-25
yora1928/CVE-2026-48908-by-yora

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

★ 2 · 2026-08-20
gagaltotal/CVE-2026-48908-SP-Page-Builder-Joomla

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

★ 0 · 2026-06-24
ayiezola/CVE-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.

★ 0 · 2026-06-25
bayu06802/CVE-2026-48908
★ 0 · 2026-07-05
CVE-2007-2447
FRESH PoCMULTI PoC
PoCs 44 ★ 61 Last push 2026-10-08 (1 day, 19 hours ago)

Fetching description from NVD…

Show 8 of 44 repositories
amriunix/CVE-2007-2447

CVE-2007-2447 - Samba usermap script

★ 61 · 2020-08-16
h3x0v3rl0rd/CVE-2007-2447

Exploit Samba smbd 3.0.20-Debian

★ 5 · 2025-06-05
Unix13/metasploitable2

PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured…

★ 4 · 2018-07-11
Ziemni/CVE-2007-2447-in-Python

Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).

★ 3 · 2021-02-22
Alien0ne/CVE-2007-2447

CVE-2007-2447 - Samba usermap script

★ 3 · 2021-06-30
xbufu/CVE-2007-2447

Exploit code for CVE-2007-2447 written in Python3.

★ 2 · 2021-10-03
JoseBarrios/CVE-2007-2447

Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username containing shell m…

★ 1 · 2020-01-20
3x1t1um/CVE-2007-2447
★ 1 · 2020-08-04
CVE-2026-18963
FRESH PoCHOTMULTI PoC
PoCs 17 ★ 114 Last push 2026-10-08 (1 day, 20 hours ago)

Fetching description from NVD…

Show 8 of 17 repositories
ynsmroztas/KeySniper

**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.

★ 114 · 2026-09-06
Snizi/CVE-2026-18963-Exploit

Exploit for KeyCloak CVE-2026-18963

★ 46 · 2026-08-20
Red-Darkin/CVE-2026-18963-keycloak

CVE-2026-18963

★ 20 · 2026-08-25
EQSTLab/CVE-2026-18963

Keycloak reset-credentials flow bypass

★ 17 · 2026-09-28
kyos-public/keycloak-cve-2026-18963-hunt

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

★ 16 · 2026-08-24
prot0tw/Keycloak_CVE-2026-18963_PoC

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

★ 15 · 2026-08-26
T0w0T/POC-CVE-2026-18963
★ 4 · 2026-08-24
alt3kx/CVE-2026-18963

CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector

★ 4 · 2026-08-28
CVE-2026-31857
FRESH PoCMULTI PoC
PoCs 5 ★ 1 Last push 2026-10-08 (1 day, 21 hours ago)

Fetching description from NVD…

Show 5 repositories
0Asylum/CVE-2026-31857

CraftCMS has an RCE vulnerability via relational conditionals in the control panel

★ 1 · 2026-09-30
0xTatsuki/CVE-2026-31857

Craft CMS RCE via relational conditionals in the control panel

★ 0 · 2026-10-01
WhiteMachin3/CVE-2026-31857

CVE-2026-31857 - Craft CMS authenticated RCE timing verifier.

★ 0 · 2026-10-05
kaizoku73/CVE-2026-31857-PoC

Proof of Concept for CVE-2026-31857, an authenticated Remote Code Execution vulnerability in Craft CMS caused by unsafe processing of user-controlled Twig expr…

★ 0 · 2026-10-08
< Prev Page 4 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.