Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2017-0199
FRESH PoCHOTMULTI PoC
PoCs 23 ★ 725 Last push 2026-10-08 (2 days, 1 hour ago)

Fetching description from NVD…

Show 8 of 23 repositories
bhdresh/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Of…

★ 725 · 2017-11-19
haibara3839/CVE-2017-0199-master

CVE-2017-0199

★ 16 · 2017-04-19
NotAwful/CVE-2017-0199-Fix

Quick and dirty fix to OLE2 executing code via .hta

★ 13 · 2017-04-24
SyFi/cve-2017-0199
★ 12 · 2017-04-13
Exploit-install/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…

★ 7 · 2017-04-22
jacobsoo/RTF-Cleaner

RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759

★ 3 · 2017-12-08
mzakyz666/PoC-CVE-2017-0199

Exploit toolkit for vulnerability RCE Microsoft RTF

★ 2 · 2017-04-22
n1shant-sinha/CVE-2017-0199

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…

★ 2 · 2017-04-23
CVE-2026-42978
FRESH PoCMULTI PoC
PoCs 5 ★ 68 Last push 2026-10-08 (2 days, 4 hours ago)

Fetching description from NVD…

Show 5 repositories
SyntaxMethod/CVE-2026-42978-PoC-Research

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Secur…

★ 68 · 2026-09-11
grizzzer/CVE-2026-42978-PoC-Research

CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW detection ru…

★ 28 · 2026-06-23
coactionbrittlemaidenhair51/CVE-2026-42978-PoC-Research

Exploit and analyze CVE-2026-42978 with a Windows Push Notifications module for AI security, multi-protocol terminal, and autonomous agent suite.

★ 0 · 2026-10-08
coactionbrittlemaidenhair51/coactionbrittlemaidenhair51.github.io

Explore and validate CVE-2026-42978 PoC with an integrated AI security tool, multi-protocol terminal, and autonomous agent suite for Windows Push Notifications.

★ 0 · 2026-09-28
CVE-2026-24061
FRESH PoCHOTMULTI PoC
PoCs 70 ★ 208 Last push 2026-10-08 (2 days, 4 hours ago)

Fetching description from NVD…

Show 8 of 70 repositories
SafeBreach-Labs/CVE-2026-24061

Exploitation of CVE-2026-24061

★ 208 · 2026-01-22
JayGLXR/CVE-2026-24061-POC
★ 68 · 2026-01-22
ZeroDayEvil/CVE-2026-24061
★ 22 · 2026-09-28
parameciumzhang/Tell-Me-Root

基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具

★ 21 · 2026-01-23
Lingzesec/CVE-2026-24061-GUI

CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具

★ 17 · 2026-01-28
leonjza/inetutils-telnetd-auth-bypass

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

★ 12 · 2026-01-22
Chocapikk/CVE-2026-24061
★ 12 · 2026-01-22
ekomsSavior/telnet_scan

scanner/exploiter CVE-2026-24061 & CVE-2026-32746

★ 12 · 2026-05-22
CVE-2026-49049
FRESH PoCMULTI PoC
PoCs 8 ★ 4 Last push 2026-10-08 (2 days, 7 hours ago)

Fetching description from NVD…

Show 8 repositories
shinthink/CVE-2026-49049

Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler

★ 4 · 2026-07-04
frada321/asdsadsadasdasdsadsad

 CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension

★ 0 · 2026-07-05
Dr-D25/CVE-2026-49049
★ 0 · 2026-07-10
ExDev994/CVE-2026-49049

CVE-2026-49049 Helix3 (JoomShaper) Joomla Unauthenticated AJAX RCE Scanner

★ 0 · 2026-07-13
6ickzone/Helix3-Mass-Exploiter

Mass Exploiter for CVE-2026-49049

★ 0 · 2026-09-21
Jenderal92/CVE-2026-49049

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PH…

★ 0 · 2026-08-02
MataKucing-OFC/CVE-2026-49049
★ 0 · 2026-09-12
theendofabbys/CVE-2026-49049
★ 0 · 2026-10-08
CVE-2026-56291
FRESH PoCMULTI PoC
PoCs 5 ★ 2 Last push 2026-10-08 (2 days, 7 hours ago)

Fetching description from NVD…

Show 5 repositories
shinthink/CVE-2026-56291

Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV

★ 2 · 2026-07-11
0xdenis77/CVE-2026-56291

Mendeteksi versi (passive detection) & Exploitation CVE POC

★ 1 · 2026-07-13
rimbadirgantara/CVE-2026-56291.yaml

nuclei template for CVE-2026-56291

★ 0 · 2026-07-13
ChiefYoru/CVE-2026-56291_PoC

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

★ 0 · 2026-07-18
theendofabbys/CVE-2026-56291
★ 0 · 2026-10-08
CVE-2026-48907
FRESH PoCMULTI PoC
PoCs 20 ★ 64 Last push 2026-10-08 (2 days, 7 hours ago)

Fetching description from NVD…

Show 8 of 20 repositories
gh1mau/masta-cve-2026-48907

cve-2026-48907 scanner

★ 64 · 2026-06-27
ywh-jfellus/CVE-2026-48907

PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE

★ 16 · 2026-06-11
0xBlackash/CVE-2026-48907

CVE-2026-48907

★ 3 · 2026-06-12
0xgh057r3c0n/CVE-2026-48907

CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5

★ 3 · 2026-06-27
g0thamRabb1t/CVE-2026-48907-Joomla-JCE-detection

Defensive lab validation and SOC detection guidance for CVE-2026-48907 in Joomla JCE <= 2.9.99.4, including Apache/Joomla/auditd telemetry, webshell artifacts,…

★ 1 · 2026-06-18
sec0x/CVE-2026-48907
★ 1 · 2026-08-05
pssec-io/CVE-2026-48907

POC for CVE-2026-48907

★ 1 · 2026-06-30
bayu06802/CVE-2026-48907

Python & template nuclei

★ 1 · 2026-07-04
CVE-2022-29078
FRESH PoCMULTI PoC
PoCs 9 ★ 8 Last push 2026-10-08 (2 days, 9 hours ago)

Fetching description from NVD…

Show 8 of 9 repositories
miko550/CVE-2022-29078

vuln ejs 3.1.6 docker

★ 8 · 2022-09-07
l0n3m4n/CVE-2022-29078

Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"

★ 3 · 2024-11-08
chuckdu21/CVE-2022-29078

PoC for CVE-2022-29078

★ 0 · 2025-01-07
AlonNavon/npm-demo

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

★ 0 · 2026-02-15
amusedx/CVE-2022-29078
★ 0 · 2026-04-12
test-avm-714877d2df585126/vuln-ejs-critical

npm repo with ejs CVE-2022-29078 (CVSS 9.8, EPSS 32%) for Dependabot automerge testing

★ 0 · 2026-07-02
test-avm-714877d2df585126/C-test-2

Dependabot security automerge test - ejs CVE-2022-29078

★ 0 · 2026-10-08
CVE-2026-43284
FRESH PoCMULTI PoC
PoCs 40 ★ 31 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 8 of 40 repositories
linnemanlabs/dirtyfrag-arm64

arm64/aarch64 port of V4bel/dirtyfrag (CVE-2026-43284). ESP-only - rxrpc path kernel-oopses on arm64 due to flush_dcache_page

★ 31 · 2026-05-13
ankitrawatgit/DirtyFrag-Android-Root-Jailbreak

DirtyFrag Android Root is an Android app and helper module chain based on DirtyFrag (CVE-2026-43284). Tested on iQOO Z9 5G.

★ 24 · 2026-10-05
0xBlackash/CVE-2026-43284

CVE-2026-43284

★ 23 · 2026-05-08
Percivalll/Dirty-Frag-Kubernetes-PoC

A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (C…

★ 16 · 2026-05-08
liamromanis101/DirtyFrag-Detector

CVE-2026-43284/CVE-2026-43500 'DirtyFrag' Benign patch & mitigation detection script

★ 16 · 2026-05-12
haydenjames/dirty-frag-check

Read-only checker for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) Linux kernel local-root vulns

★ 7 · 2026-05-12
a2333c/DFRoot

三星 Galaxy S25 Ultra(SM-S938B)适配版 DFRoot:开机自动获取 root(DirtyFrag CVE-2026-43284 + CVE-2026-43499 双链路),全中文界面,fork 自 diabl0w/DFRoot

★ 5 · 2026-09-28
mym0us3r/DIRTY-FRAG-Detection-with-Wazuh-4.14.4

Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write

★ 3 · 2026-05-17
CVE-2024-4367
FRESH PoCHOTMULTI PoC
PoCs 27 ★ 203 Last push 2026-10-07 (2 days, 19 hours ago)

Fetching description from NVD…

Show 8 of 27 repositories
LOURC0D3/CVE-2024-4367-PoC

CVE-2024-4367 & CVE-2024-34342 Proof of Concept

★ 203 · 2024-06-07
s4vvysec/CVE-2024-4367-POC

CVE-2024-4367 arbitrary js execution in pdf js

★ 57 · 2024-05-20
Zombie-Kaiser/cve-2024-4367-PoC-fixed

PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…

★ 12 · 2024-06-13
spaceraccoon/detect-cve-2024-4367

YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js

★ 11 · 2024-05-27
snyk-labs/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 10 · 2026-10-07
UnHackerEnCapital/PDFernetRemotelo

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

★ 6 · 2024-06-20
Masamuneee/CVE-2024-4367-Analysis

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

★ 5 · 2024-09-04
clarkio/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 4 · 2024-11-10
CVE-2019-2215
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 137 Last push 2026-10-07 (2 days, 22 hours ago)

Fetching description from NVD…

Show 8 of 33 repositories
kangtastic/cve-2019-2215

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

★ 137 · 2019-10-15
timwr/CVE-2019-2215
★ 79 · 2019-11-12
sharif-dev/AndroidKernelVulnerability

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

★ 73 · 2022-09-04
0xbinder/android-kernel-exploitation-lab

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

★ 44 · 2025-04-24
DimitriFourny/cve-2019-2215

Android privilege escalation via an use-after-free in binder.c

★ 41 · 2020-04-14
LIznzn/CVE-2019-2215

Temproot for Bravia TV via CVE-2019-2215.

★ 26 · 2020-02-20
stevejubx/CVE-2019-2215

Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC

★ 17 · 2023-12-21
c3r34lk1ll3r/CVE-2019-2215

PoC for old Binder vulnerability (based on P0 exploit)

★ 14 · 2020-10-27
CVE-2022-0492
FRESH PoCMULTI PoC
PoCs 8 ★ 47 Last push 2026-10-07 (3 days ago)

Fetching description from NVD…

Show 8 repositories
PaloAltoNetworks/can-ctr-escape-cve-2022-0492

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

★ 47 · 2022-03-09
chenaotian/CVE-2022-0492

CVE-2022-0492 EXP and Analysis write up

★ 35 · 2022-03-11
SofianeHamlaoui/CVE-2022-0492-Checker

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

★ 13 · 2022-03-12
T1erno/CVE-2022-0492-Docker-Breakout-Checker-and-PoC

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

★ 8 · 2023-02-18
KianaBin/CVE-2022-0492-Container-Escape

CVE-2022-0492-Container-Escape

★ 2 · 2022-08-28
Perimora/cve_2022_0492

PoC for CVE-2022-0492

★ 0 · 2025-07-20
hgyc/CVE-stand

Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs

★ 0 · 2026-10-07
CVE-2026-39987
FRESH PoCMULTI PoC
PoCs 27 ★ 9 Last push 2026-10-07 (3 days, 2 hours ago)

Fetching description from NVD…

Show 8 of 27 repositories
Th3Purge/CVE-2026-39987

Marimo Pre Authentication RCE

★ 9 · 2026-09-08
M3PH1569/CVE-2026-39987-POC

CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)

★ 5 · 2026-07-19
keraattin/CVE-2026-39987

CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE (CVSS 9.3). Python & Nmap NSE detection scripts. Missing authentication on /terminal/ws WebSocket endpoint …

★ 1 · 2026-04-15
Nxploited/CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

★ 1 · 2026-04-18
h3raklez/CVE-2026-39987

Marimo Pre-Auth RCE

★ 1 · 2026-04-25
Wind010/CVE-2026-39987_PoC

A proof-of-concept for CVE-2026-39987

★ 1 · 2026-08-03
Ghxstsec/CVE-2026-39987
★ 1 · 2026-09-01
CVE-2026-87902
HIGHFRESH PoCMULTI PoC
CVSS 8.1 HIGH CWE-98 Published 2026-09-22 PoCs 26 ★ 38 Last push 2026-10-07 (3 days, 2 hours ago)

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Show 8 of 26 repositories
ressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable l…

★ 38 · 2026-09-22
abraxas/CVE-2026-87902

CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)

★ 35 · 2026-10-07
dinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional RCE (WP 4…

★ 13 · 2026-09-23
tc4dy/CVE-2026-87902-Toolkit

CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create,…

★ 11 · 2026-09-27
vulpecuna/CVE-2026-87902

Unauthenticated RCE on Wordpress

★ 9 · 2026-09-23
tonydelouvre/CVE-2026-87902

XWP_RCE — CVE-2026-87902 Hacker Console

★ 4 · 2026-09-29
ynsmroztas/WPSniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

★ 3 · 2026-09-23
crowsec-edtech/CVE-2026-87902

Proof of concept for vulnerability CVE-2026-87902 in Wordpress

★ 3 · 2026-09-25
CVE-2020-1472
FRESH PoCHOTMULTI PoC
PoCs 75 ★ 1837 Last push 2026-10-07 (3 days, 2 hours ago)

Fetching description from NVD…

Show 8 of 75 repositories
bvcyber/CVE-2020-1472

Test tool for CVE-2020-1472

★ 1837 · 2025-06-27
dirkjanm/CVE-2020-1472

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

★ 1329 · 2020-11-03
risksense/zerologon

Exploit for zerologon cve-2020-1472

★ 708 · 2020-10-15
VoidSec/CVE-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

★ 399 · 2020-11-05
bb00/zer0dump

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

★ 179 · 2023-03-02
mstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

★ 113 · 2020-09-16
Rvn0xsy/ZeroLogon

CVE-2020-1472 C++

★ 83 · 2022-09-02
zeronetworks/zerologon

Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB

★ 61 · 2023-05-01
CVE-2016-5195
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 1015 Last push 2026-10-07 (3 days, 4 hours ago)

Fetching description from NVD…

Show 8 of 62 repositories
timwr/CVE-2016-5195

CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

★ 1015 · 2021-02-03
firefart/dirtycow

Dirty Cow exploit - CVE-2016-5195

★ 932 · 2025-07-30
scumjr/dirtycow-vdso

PoC for Dirty COW (CVE-2016-5195)

★ 512 · 2022-03-16
gbonacini/CVE-2016-5195

A CVE-2016-5195 exploit example.

★ 341 · 2017-03-21
r1is/CVE-2022-0847

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…

★ 282 · 2023-02-02
hyln9/VIKIROOT

CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow

★ 271 · 2017-01-27
Brucetg/DirtyCow-EXP

编译好的脏牛漏洞(CVE-2016-5195)EXP

★ 141 · 2018-05-27
DavidBuchanan314/cowroot

Universal Android root tool based on CVE-2016-5195. Watch this space.

★ 32 · 2016-10-29
CVE-2026-33439
FRESH PoCMULTI PoC
PoCs 7 ★ 11 Last push 2026-10-07 (3 days, 8 hours ago)

Fetching description from NVD…

Show 7 repositories
TheMalwareGuardian/CVE-2026-33439

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

★ 11 · 2026-05-01
infernosalex/CVE-2026-33439-Python-PoC

Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

★ 4 · 2026-09-12
Ibonok/CVE-2026-33439-PoC

CVE-2026-33439

★ 2 · 2026-04-28
shreyas-malhotra/CVE-2026-33439-OpenAM

Vulnerable endpoint description for CVE-2026-33439 in OpenAM

★ 0 · 2026-04-27
JonasChen0103/CVE-2026-33439-PoC

CVE-2026-33439 OpenAM pre-auth RCE PoC

★ 0 · 2026-09-19
rh33t/CVE-2026-33439-Poc

Proof of concept for CVE-2026-33439, an unauthenticated RCE in OpenAM via Java deserialization

★ 0 · 2026-09-29
amis13/openam-clean

CVE-2026-33439

★ 0 · 2026-10-07
CVE-2022-0185
FRESH PoCHOTMULTI PoC
PoCs 11 ★ 378 Last push 2026-10-07 (3 days, 8 hours ago)

Fetching description from NVD…

Show 8 of 11 repositories
Crusaders-of-Rust/CVE-2022-0185

CVE-2022-0185

★ 378 · 2022-04-25
chenaotian/CVE-2022-0185

CVE-2022-0185 POC and Docker and Analysis write up

★ 37 · 2022-05-24
veritas501/CVE-2022-0185-PipeVersion

CVE-2022-0185 exploit rewritten with pipe primitive

★ 16 · 2022-04-05
featherL/CVE-2022-0185-exploit

CVE-2022-0185 exploit

★ 3 · 2022-11-02
dcheng69/CVE-2022-0185-Case-Study
★ 3 · 2024-05-09
khaclep007/CVE-2022-0185
★ 0 · 2022-01-27
sandesh9978/CVE-2022-0185-Analysis-and-Exploit

Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.

★ 0 · 2026-03-20
CVE-2026-75650
FRESH PoCMULTI PoC
PoCs 6 ★ 8 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 6 repositories
fortbridge/stylesmuggler

Private HTTP-only reproduction of CVE-2026-75650 StyleSmuggler

★ 8 · 2026-09-12
dinosn/cve-2026-75650-magento-validation-lab

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

★ 6 · 2026-09-12
disrex-group/stylesmuggler-adobe-patches

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magen…

★ 5 · 2026-09-08
jithinkrishnanrs/stylesmuggler-ioc-toolkit

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence ar…

★ 0 · 2026-09-17
disrex-group/stylesmuggler-adobe-patches-mageos

composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-ado…

★ 0 · 2026-09-08
abraxas/CVE-2026-75650

CVE-2026-75650 - Magento Open Source - Critical 10.0 - Unauthenticated POST /graphql - Unauthenticated Remote Code Execution (StyleSmuggler SSTI)

★ 0 · 2026-10-07
CVE-2026-3888
FRESH PoCMULTI PoC
PoCs 8 ★ 19 Last push 2026-10-06 (3 days, 18 hours ago)

Fetching description from NVD…

Show 8 repositories
noambouillet/CVE-2026-3888

Linux LPE via snap-confine + systemd-tmpfiles, explained in depth

★ 5 · 2026-04-02
netw0rk7/CVE-2026-3888-PoC
★ 3 · 2026-03-23
fevar54/CVE-2026-3888-POC-all-from-the-Qualys-platform.

PoC de CVE-2026-3888: condicion de carrera en snapd para escalada a root.

★ 2 · 2026-03-18
AlanNewberry/CVE-2026-3888-snap-confine-privilege-escalation

Exploit para CVE-2026-3888: race condition en snap-confine con hijack del loader para escalar a root en Linux.

★ 1 · 2026-10-06
Many-Hat-Group/Ubuntu-CVE-2026-3888-patcher

This is a script designed for deployment on ubuntu instances patching the CVE-2026-3888 exploit

★ 0 · 2026-03-19
DanielTangnes/CVE-2026-3888
★ 0 · 2026-05-19
hewhomusntbenamed/CVE-2026-3888-fixed

CVE-2026-3888 — snap-confine / systemd-tmpfiles SUID LPE (fixed race_pid.txt issue)

★ 0 · 2026-05-12
CVE-2026-67401
FRESH PoCMULTI PoC
PoCs 5 ★ 5 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 5 repositories
imbas007/CVE-2026-67401

PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…

★ 5 · 2026-09-17
axedos/CVE-2026-67401

poc in python for CVE-2026-67401

★ 3 · 2026-09-09
HORKimhab/CVE-2026-67401

CVE-2026-67401 - Draft or TODO

★ 0 · 2026-09-09
jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi

CVE-2026-67401 cPanel & WHM EmailTrack SQL Injection — IOC scanner, compromise detection, patch verification, incident response and remediation toolkit.

★ 0 · 2026-09-13
hitechcloud-vietnam/CVE-2026-67401

PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…

★ 0 · 2026-10-06
CVE-2026-41940
FRESH PoCHOTMULTI PoC
PoCs 76 ★ 509 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 76 repositories
ynsmroztas/cPanelSniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

★ 509 · 2026-05-01
assetnote/cpanel2shell-scanner

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

★ 92 · 2026-05-18
XsanFlip/poc-cpanel-cve-2026-41940
★ 64 · 2026-05-01
adriyansyah-mf/cve-2026-41940-poc
★ 28 · 2026-04-30
ZeroDayEvil/CVE-2026-41940-PoC
★ 28 · 2026-09-28
Sachinart/CVE-2026-41940-cpanel-0day

CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani

★ 25 · 2026-04-29
ilmndwntr/CVE-2026-41940-MASS-EXPLOIT

CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT

★ 13 · 2026-04-30
rfxn/cpanel-sessionscribe

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…

★ 13 · 2026-05-21
CVE-2024-21413
FRESH PoCHOTMULTI PoC
PoCs 42 ★ 777 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 42 repositories
xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

★ 777 · 2024-02-19
CMNatic/CVE-2024-21413

CVE-2024-21413 PoC for THM Lab

★ 289 · 2024-03-13
duy-31/CVE-2024-21413

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

★ 156 · 2024-02-17
ThemeHackers/CVE-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

★ 25 · 2025-06-05
r00tb1t/CVE-2024-21413-POC

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

★ 17 · 2024-02-16
mmathivanan17/CVE-2024-21413

Outlook exploitation

★ 11 · 2025-11-30
ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. Monik…

★ 4 · 2024-02-24
CVE-2026-43494
FRESH PoCMULTI PoC
PoCs 7 ★ 2 Last push 2026-10-06 (3 days, 23 hours ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-43494

CVE-2026-43494

★ 2 · 2026-05-23
jayhutajulu1/CVE-2026-43494-PinTheft-PoC

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…

★ 1 · 2026-07-16
Koshmare-Blossom/PinTheft-asm

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

★ 1 · 2026-05-28
suominen/pintheft

Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation

★ 0 · 2026-10-06
Kagantua/PinTheft-go

A Go implementation of PinTheft (CVE-2026-43494)

★ 0 · 2026-05-22
tanzz1337/CVE-2026-43494-PinTheft-PoC

Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…

★ 0 · 2026-05-25
CVE-2026-64564
FRESH PoCMULTI PoC
PoCs 5 ★ 7 Last push 2026-10-06 (3 days, 23 hours ago)

Fetching description from NVD…

Show 5 repositories
ethanolgolf/CVE-2026-64564

LPE on Deb

★ 7 · 2026-08-10
HackSpeak/CVE-2026-64564

SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing

★ 7 · 2026-08-08
suominen/sctphantom

Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free

★ 1 · 2026-10-06
yandex-cloud-examples/yc-mk8s-sctphantom-mitigation

DaemonSet для митигации уязвимости CVE-2026-64564 (SCTPhantom)

★ 0 · 2026-08-11
CVE-2026-53359
FRESH PoCMULTI PoC
PoCs 7 ★ 6 Last push 2026-10-06 (3 days, 23 hours ago)

Fetching description from NVD…

Show 7 repositories
Aoripus-LTD/Januscape-Hotfix

Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — c…

★ 6 · 2026-07-08
0xBlackash/CVE-2026-53359

CVE-2026-53359

★ 4 · 2026-07-08
chuzhongyun/CVE-2026-53359-Kernel-Fix

Linux 内核升级指南 - 修复 CVE-2026-53359

★ 2 · 2026-07-08
xj2268-TA/KVM-Januscape

CVE-2026-53359漏洞补丁

★ 2 · 2026-07-09
HORKimhab/CVE-2026-53359

CVE-2026-53359 - Draft

★ 0 · 2026-07-07
suominen/januscape

Tracking Januscape (CVE-2026-53359), the KVM/x86 guest-to-host escape

★ 0 · 2026-10-06
ndouglas-cloudsmith/CVE-2026-53359

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerabili…

★ 0 · 2026-07-15
< Prev Page 5 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.