Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
355PoC updated in 7 days
filters
803 results
PoCs 23
★ 725
Last push 2026-10-08 (2 days, 1 hour ago)
Fetching description from NVD…
Show 8 of 23 repositories
bhdresh/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Of…
★ 725 · 2017-11-19
Exploit-install/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…
★ 7 · 2017-04-22
jacobsoo/RTF-Cleaner
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
★ 3 · 2017-12-08
n1shant-sinha/CVE-2017-0199
Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could generate a malici…
★ 2 · 2017-04-23
PoCs 5
★ 68
Last push 2026-10-08 (2 days, 4 hours ago)
Fetching description from NVD…
Show 5 repositories
SyntaxMethod/CVE-2026-42978-PoC-Research
CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module for AI Secur…
★ 68 · 2026-09-11
grizzzer/CVE-2026-42978-PoC-Research
CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW detection ru…
★ 28 · 2026-06-23
PoCs 70
★ 208
Last push 2026-10-08 (2 days, 4 hours ago)
Fetching description from NVD…
Show 8 of 70 repositories
PoCs 8
★ 4
Last push 2026-10-08 (2 days, 7 hours ago)
Fetching description from NVD…
Show 8 repositories
shinthink/CVE-2026-49049
Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler
★ 4 · 2026-07-04
Jenderal92/CVE-2026-49049
Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed and raw PH…
★ 0 · 2026-08-02
PoCs 5
★ 2
Last push 2026-10-08 (2 days, 7 hours ago)
Fetching description from NVD…
Show 5 repositories
shinthink/CVE-2026-56291
Balbooa Forms (com_baforms) < 2.4.1 — Unauthenticated File Upload to RCE via form.uploadAttachmentFile | CVSS 9.8 | CISA KEV
★ 2 · 2026-07-11
ChiefYoru/CVE-2026-56291_PoC
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
★ 0 · 2026-07-18
PoCs 20
★ 64
Last push 2026-10-08 (2 days, 7 hours ago)
Fetching description from NVD…
Show 8 of 20 repositories
PoCs 9
★ 8
Last push 2026-10-08 (2 days, 9 hours ago)
Fetching description from NVD…
Show 8 of 9 repositories
AlonNavon/npm-demo
Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation
★ 0 · 2026-02-15
PoCs 40
★ 31
Last push 2026-10-07 (2 days, 16 hours ago)
Fetching description from NVD…
Show 8 of 40 repositories
linnemanlabs/dirtyfrag-arm64
arm64/aarch64 port of V4bel/dirtyfrag (CVE-2026-43284). ESP-only - rxrpc path kernel-oopses on arm64 due to flush_dcache_page
★ 31 · 2026-05-13
Percivalll/Dirty-Frag-Kubernetes-PoC
A proof-of-concept demonstrating how a default, unprivileged Kubernetes Pod can achieve node-level code execution on Amazon EKS by exploiting the Dirty Frag (C…
★ 16 · 2026-05-08
a2333c/DFRoot
三星 Galaxy S25 Ultra(SM-S938B)适配版 DFRoot:开机自动获取 root(DirtyFrag CVE-2026-43284 + CVE-2026-43499 双链路),全中文界面,fork 自 diabl0w/DFRoot
★ 5 · 2026-09-28
PoCs 27
★ 203
Last push 2026-10-07 (2 days, 19 hours ago)
Fetching description from NVD…
Show 8 of 27 repositories
Zombie-Kaiser/cve-2024-4367-PoC-fixed
PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…
★ 12 · 2024-06-13
snyk-labs/pdfjs-vuln-demo
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
★ 10 · 2026-10-07
clarkio/pdfjs-vuln-demo
This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367
★ 4 · 2024-11-10
PoCs 33
★ 137
Last push 2026-10-07 (2 days, 22 hours ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 8
★ 47
Last push 2026-10-07 (3 days ago)
Fetching description from NVD…
Show 8 repositories
hgyc/CVE-stand
Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs
★ 0 · 2026-10-07
PoCs 27
★ 9
Last push 2026-10-07 (3 days, 2 hours ago)
Fetching description from NVD…
Show 8 of 27 repositories
keraattin/CVE-2026-39987
CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE (CVSS 9.3). Python & Nmap NSE detection scripts. Missing authentication on /terminal/ws WebSocket endpoint …
★ 1 · 2026-04-15
CVSS 8.1 HIGH
CWE-98
Published 2026-09-22
PoCs 26
★ 38
Last push 2026-10-07 (3 days, 2 hours ago)
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
Show 8 of 26 repositories
ressl/cve-2026-87902-poc
PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable l…
★ 38 · 2026-09-22
abraxas/CVE-2026-87902
CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)
★ 35 · 2026-10-07
dinosn/cve-2026-87902-wordpress-lfi-lab
Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional RCE (WP 4…
★ 13 · 2026-09-23
tc4dy/CVE-2026-87902-Toolkit
CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create,…
★ 11 · 2026-09-27
ynsmroztas/WPSniper
CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.
★ 3 · 2026-09-23
PoCs 75
★ 1837
Last push 2026-10-07 (3 days, 2 hours ago)
Fetching description from NVD…
Show 8 of 75 repositories
bb00/zer0dump
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
★ 179 · 2023-03-02
PoCs 62
★ 1015
Last push 2026-10-07 (3 days, 4 hours ago)
Fetching description from NVD…
Show 8 of 62 repositories
r1is/CVE-2022-0847
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…
★ 282 · 2023-02-02
hyln9/VIKIROOT
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
★ 271 · 2017-01-27
PoCs 7
★ 11
Last push 2026-10-07 (3 days, 8 hours ago)
Fetching description from NVD…
Show 7 repositories
PoCs 11
★ 378
Last push 2026-10-07 (3 days, 8 hours ago)
Fetching description from NVD…
Show 8 of 11 repositories
PoCs 6
★ 8
Last push 2026-10-07 (3 days, 9 hours ago)
Fetching description from NVD…
Show 6 repositories
disrex-group/stylesmuggler-adobe-patches
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magen…
★ 5 · 2026-09-08
abraxas/CVE-2026-75650
CVE-2026-75650 - Magento Open Source - Critical 10.0 - Unauthenticated POST /graphql - Unauthenticated Remote Code Execution (StyleSmuggler SSTI)
★ 0 · 2026-10-07
PoCs 8
★ 19
Last push 2026-10-06 (3 days, 18 hours ago)
Fetching description from NVD…
Show 8 repositories
PoCs 5
★ 5
Last push 2026-10-06 (3 days, 20 hours ago)
Fetching description from NVD…
Show 5 repositories
imbas007/CVE-2026-67401
PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…
★ 5 · 2026-09-17
hitechcloud-vietnam/CVE-2026-67401
PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…
★ 0 · 2026-10-06
PoCs 76
★ 509
Last push 2026-10-06 (3 days, 20 hours ago)
Fetching description from NVD…
Show 8 of 76 repositories
rfxn/cpanel-sessionscribe
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…
★ 13 · 2026-05-21
PoCs 42
★ 777
Last push 2026-10-06 (3 days, 20 hours ago)
Fetching description from NVD…
Show 8 of 42 repositories
duy-31/CVE-2024-21413
Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC
★ 156 · 2024-02-17
PoCs 7
★ 2
Last push 2026-10-06 (3 days, 23 hours ago)
Fetching description from NVD…
Show 7 repositories
jayhutajulu1/CVE-2026-43494-PinTheft-PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…
★ 1 · 2026-07-16
suominen/pintheft
Tracking PinTheft (CVE-2026-43494, CVE-2026-43502), the RDS zerocopy double-free privilege escalation
★ 0 · 2026-10-06
tanzz1337/CVE-2026-43494-PinTheft-PoC
Proof-of-concept for CVE-2026-43494 (PinTheft): Linux LPE via RDS zerocopy refcount bug + io_uring fixed buffers → SUID page-cache overwrite. Authorized resear…
★ 0 · 2026-05-25
PoCs 5
★ 7
Last push 2026-10-06 (3 days, 23 hours ago)
Fetching description from NVD…
Show 5 repositories
HackSpeak/CVE-2026-64564
SCTPhantom (CVE-2026-64564) SCTP ASCONF DEL-IP UAF LPE PoC (Debian 13 6.12.95) — community PoC mirror, MIT; for authorized security testing
★ 7 · 2026-08-08
suominen/sctphantom
Tracking SCTPhantom (CVE-2026-64564), the Linux kernel SCTP ASCONF transport use-after-free
★ 1 · 2026-10-06
PoCs 7
★ 6
Last push 2026-10-06 (3 days, 23 hours ago)
Fetching description from NVD…
Show 7 repositories
Aoripus-LTD/Januscape-Hotfix
Complete fix collection for the CVE-2026-53359 guest-to-host escape vulnerability in the KVM/x86 shadow MMU. From zero-downtime livepatch to kernel upgrade — c…
★ 6 · 2026-07-08
ndouglas-cloudsmith/CVE-2026-53359
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerabili…
★ 0 · 2026-07-15
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.