Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-44011
MULTI PoC
PoCs 6 ★ 5 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 6 repositories
4xura/CVE-2026-44011-craftcms-auth-rce

The PoC of CVE-2026-44011: Craft CMS RCE with an authenticated user.

★ 5 · 2026-09-27
Cyberuser-hash/CVE-2026-44011-craft-rce-poc

CVE-2026-44011-craft-rce-poc

★ 2 · 2026-09-27
khush-613/CVE-2026-44011-poc
★ 1 · 2026-09-27
TRX-0/CVE-2026-44011-craftcms-rce

Craft CMS CVE-2026-44011 condition FieldLayout RCE PoC

★ 0 · 2026-09-21
DENNISDGR/CVE-2026-44011-poc

Authenticated Craft CMS RCE PoC for CVE-2026-44011

★ 0 · 2026-09-27
0xyngtg/CraftCMS-CVE-2026-44011-PoC-RCE

This is a PoC of the CVE-2026-44011 found by precicom-vincent-tl. For more details check: https://github.com/advisories/GHSA-qrgm-p9w5-rrfw

★ 0 · 2026-10-02
CVE-2018-12533
MULTI PoC
PoCs 5 ★ 9 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 5 repositories
llamaonsecurity/CVE-2018-12533

RF-14310 / CVE-2018-12533 - Payload generator

★ 9 · 2022-07-07
Pastea/CVE-2018-12533
★ 1 · 2021-11-08
LucasKatashi/paint2die

Simplest and most reliable RichFaces Paint2DResource CVE-2018-12533 RF-14310 exploit PoC

★ 1 · 2025-11-25
arslanben/richfaces-paint2d-lab

Deliberately vulnerable CTF lab reproducing CVE-2018-12533 (RichFaces Paint2DResource EL injection) end to end.

★ 1 · 2026-10-01
CVE-2026-90817
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-73, CWE-94 Published 2026-09-20 PoCs 5 ★ 2 Last push 2026-10-01 (1 week, 1 day ago)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.

Show 5 repositories
murrez/CVE-2026-90817

Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation.

★ 2 · 2026-09-21
yulisec/CVE-2026-90817
★ 1 · 2026-09-24
securifera/CVE-2026-90817

REDCap DataImport RCE

★ 1 · 2026-10-01
ExDev994/CVE-2026-90817
★ 0 · 2026-09-21
Farih123/CVE-2026-90817
★ 0 · 2026-09-26
CVE-2024-21626
MULTI PoC
PoCs 19 ★ 80 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 19 repositories
NitroCao/CVE-2024-21626

PoC and Detection for CVE-2024-21626

★ 80 · 2024-02-06
V0WKeep3r/CVE-2024-21626-runcPOC
★ 6 · 2024-02-05
cdxiaodong/CVE-2024-21626

CVE-2024-21626-poc-research-Reappearance-andtodo

★ 5 · 2024-02-02
zhangguanzhang/CVE-2024-21626
★ 4 · 2024-02-02
laysakura/CVE-2024-21626-demo

Container Runtime Meetup #5 のLT用のデモ

★ 3 · 2024-02-02
Sk3pper/CVE-2024-21626
★ 2 · 2024-11-10
KubernetesBachelor/CVE-2024-21626

POC

★ 2 · 2025-05-27
dorser/cve-2024-21626
★ 2 · 2024-04-16
CVE-2023-28432
MULTI PoC
PoCs 20 ★ 37 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 20 repositories
MzzdToT/CVE-2023-28432

MinIO敏感信息泄露漏洞批量扫描poc&exp

★ 37 · 2023-03-24
Mr-xn/CVE-2023-28432

CVE-2023-28434 nuclei templates

★ 34 · 2023-03-23
acheiii/CVE-2023-28432

CVE-2023-28432 POC

★ 15 · 2023-03-24
Chocapikk/CVE-2023-28432

Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.

★ 11 · 2026-01-08
gobysec/CVE-2023-28432

MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)

★ 10 · 2023-03-24
Cuerz/CVE-2023-28432

CVE-2023-28432 MinIO敏感信息泄露检测脚本

★ 10 · 2023-03-29
Okaytc/minio_unauth_check

CVE-2023-28432,minio未授权访问检测工具

★ 7 · 2023-03-24
yTxZx/CVE-2023-28432
★ 3 · 2023-10-20
CVE-2024-3094
HOTMULTI PoC
PoCs 84 ★ 3551 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 84 repositories
amlweems/xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

★ 3551 · 2024-04-03
lockness-Ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

★ 146 · 2024-04-02
FabioBaroni/CVE-2024-3094-checker

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

★ 72 · 2024-03-31
robertdfrench/ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

★ 60 · 2026-09-25
byinarie/CVE-2024-3094-info

Information for CVE-2024-3094

★ 54 · 2024-04-01
jfrog/cve-2024-3094-tools
★ 44 · 2024-04-07
gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be v…

★ 26 · 2024-04-07
0xlane/xz-cve-2024-3094

XZ Backdoor Extract(Test on Ubuntu 23.10)

★ 17 · 2024-04-02
CVE-2025-24813
HOTMULTI PoC
PoCs 58 ★ 195 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813

his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…

★ 195 · 2025-03-14
iSee857/CVE-2025-24813-PoC

Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)

★ 98 · 2025-04-02
drcrypterdotru/Apache-GOExploiter

Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast

★ 20 · 2025-10-05
mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-

Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)

★ 19 · 2025-05-25
charis3306/CVE-2025-24813

CVE-2025-24813利用工具

★ 16 · 2025-03-16
qzy0x/cve-2025-24813_poc

cve-2025-24813验证脚本

★ 11 · 2025-03-14
Franconyu/Poc_for_CVE-2025-24813

CVE-2025-24813 poc

★ 9 · 2025-04-11
x00byte/PutScanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

★ 9 · 2025-07-19
CVE-2017-0144
HOTMULTI PoC
PoCs 25 ★ 339 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 25 repositories
peterpt/eternal_scanner

An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)

★ 339 · 2024-07-31
AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint

This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a…

★ 15 · 2025-07-10
AtithKhawas/autoblue

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …

★ 5 · 2024-12-30
sethwhy/BlueDoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…

★ 2 · 2024-12-22
0xBlackash/CVE-2017-0144

CVE-2017-0144

★ 2 · 2026-06-14
kimocoder/eternalblue

CVE-2017-0144

★ 1 · 2024-04-01
MedX267/EternalBlue-Vulnerability-Scanner

This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.

★ 1 · 2025-02-03
CVE-2025-5548
MULTI PoC
PoCs 30 ★ 2 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 30 repositories
mk017-hk/CVE-2025-5548

Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulner…

★ 2 · 2026-05-08
TheMalwareGuardian/CVE-2025-5548

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

★ 1 · 2026-03-23
JSantos1990/CVE-2025-5548

🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation, lab enviro…

★ 0 · 2026-03-18
alanschmidt81/CVE-2025-5548
★ 0 · 2026-03-15
javyan05/CVE-2025-5548

Entorno y explotación de la vulnerabilidad CVE-2025-5548

★ 0 · 2026-03-16
charlyrr/CVE-2025-5548
★ 0 · 2026-03-18
celiagomezserra/CVE-2025-5548

Explotación de la vulnerabilidad CVE-2025-5548, paso a paso

★ 0 · 2026-03-19
CVE-2025-8110
MULTI PoC
PoCs 20 ★ 31 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 20 repositories
zAbuQasem/gogs-CVE-2025-8110

CVE-2025-8110 PoC

★ 31 · 2025-12-24
rxerium/CVE-2025-8110

Detection template for CVE-2025-8110

★ 22 · 2025-12-11
Ghxstsec/CVE-2025-8110
★ 5 · 2026-04-20
joaquinrrr/CVE-2025-8110

PoC exploit for CVE-2025-8110

★ 5 · 2026-06-25
kayl22/cve-2025-8110-GOGS-RCE

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then trigge…

★ 4 · 2026-04-11
Shirouuu/CVE-2025-8110-gogs-poc

PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink

★ 4 · 2026-07-17
3jee/CVE-2025-8110

CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API

★ 2 · 2026-04-11
CVE-2026-33825
MULTI PoC
PoCs 6 ★ 10 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 6 repositories
Letlaka/redsun-bluehammer-undefend-detection-pack

Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.

★ 10 · 2026-05-05
0xBlackash/CVE-2026-33825

CVE-2026-33825

★ 8 · 2026-05-20
Joe1sn/CVE-2026-33825

RedSun PoC for self use

★ 3 · 2026-05-02
Bilal3755/Detecting_blue_hammer_vuln

Threat hunting query for bluehammer CVE windows CVE-2026-33825

★ 0 · 2026-04-20
kaleth4/CVE-2026-33825
★ 0 · 2026-04-22
anasabugaddara-ux/defender-bluehammer-audit

Defensive Metasploit post module for CVE-2026-33825 (BlueHammer): Defender version/posture detection + compromise-hunt. Detection only.

★ 0 · 2026-10-01
CVE-2026-58138
MULTI PoC
PoCs 7 ★ 3 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-58138

CVE-2026-58138

★ 3 · 2026-09-05
Ch4120N/CVE-2026-58138

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

★ 2 · 2026-07-15
BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

★ 0 · 2026-06-30
seqra/cve-2026-58138
★ 0 · 2026-07-15
0xgh057r3c0n/CVE-2026-58138

CVE-2026-58138 - Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator

★ 0 · 2026-07-22
Procjevt/CVE-2026-58138
★ 0 · 2026-07-27
Ez4rd1x1/CVE-2026-58138-Research

critical-severity unauthenticated Remote Code Execution (RCE) vulnerability impacting Orkes Conductor

★ 0 · 2026-10-01
CVE-2026-3854
MULTI PoC
PoCs 7 ★ 9 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 7 repositories
royaleybovich/CVE-2026-3854-lab
★ 9 · 2026-10-01
lysophavin18/CVE-2026-3854-PoC

GitHub RCE via X-Stat Push Option Injection

★ 2 · 2026-04-29
5kr1pt/CVE-2026-3854
★ 0 · 2026-04-28
LACHHAB-Anas/Exploit_CVE-2026-3854

Details about CVE-2026-3854

★ 0 · 2026-04-28
simondankelmann/cve-2026-3854-test

CVE-2026-3854 patch bypass testing

★ 0 · 2026-04-29
isagoakira/ghes-cve-scanner

GHES CVE Scanner — Defensive security tool for detecting CVE-2026-3854 (Git Push RCE) and CVE-2026-4821 (Management Console proxy injection) in GitHub …

★ 0 · 2026-05-05
ridhinva/ghe-push-option-rce-scanner

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

★ 0 · 2026-08-07
CVE-2023-38831
HOTMULTI PoC
PoCs 60 ★ 783 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 60 repositories
b1tg/CVE-2023-38831-winrar-exploit

CVE-2023-38831 winrar exploit generator

★ 783 · 2023-11-26
Garck3h/cve-2023-38831

一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。

★ 126 · 2023-08-27
ignis-sec/CVE-2023-38831-RaRCE

An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23

★ 113 · 2023-08-27
BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

★ 91 · 2023-08-24
HDCE-inc/CVE-2023-38831

CVE-2023-38831 PoC (Proof Of Concept)

★ 89 · 2024-08-04
knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831

Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)

★ 40 · 2023-08-28
Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE

Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.

★ 22 · 2023-08-31
xaitax/WinRAR-CVE-2023-38831

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …

★ 17 · 2023-09-08
CVE-2025-59528
MULTI PoC
PoCs 13 ★ 1 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
UsifAraby/CVE-2025-59528-POC

CVE-2025-59528 - FlowiseAI CustomMCP Remote Code Execution

★ 1 · 2026-04-13
vanhari/CVE-2025-59528

CVE-2025-59528 Proof of Concept

★ 1 · 2026-04-13
maradonam18/-CVE-2025-59528-PoC

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also used in HTB s…

★ 1 · 2026-04-15
arensballiu/Flowise-RCE-CVE-2025-59528

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the /api/v1/node-load-method/customMCP endpoint…

★ 1 · 2026-09-28
mananispiwpiw/CVE-2025-59528-PoC

CVE-2025-59528 Proof of Concept

★ 1 · 2026-05-08
NymiiTechTips/CVE-2025-59528

Technical PoC for CVE-2025-59528 (Flowise < 3.0.5), demonstrating authenticated RCE through customMCP mcpServerConfig injection, with clear bilingual documenta…

★ 1 · 2026-05-16
corey-farley/CVE-2025-59528-Flowise-RCE

Authenticated RCE PoC for Flowise version <= 3.0.5 via CustomMCP Node (CVE-2025-59528)

★ 1 · 2026-05-17
CVE-2024-21338
HOTMULTI PoC
PoCs 9 ★ 332 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 9 repositories
hakaioffsec/CVE-2024-21338

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 332 · 2024-04-16
Crowdfense/CVE-2024-21338

Windows AppLocker Driver (appid.sys) LPE

★ 81 · 2024-07-29
tykawaii98/CVE-2024-21338_PoC
★ 40 · 2024-06-23
Zombie-Kaiser/CVE-2024-21338-x64-build-

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 7 · 2024-05-22
MistyFir/CVE-2024-21338-Exploit
★ 7 · 2026-04-06
UMU618/CVE-2024-21338

Fork of https://github.com/hakaioffsec/CVE-2024-21338

★ 2 · 2024-04-17
wusijie/CVE-2024-21338-1

PoC for the Untrusted Pointer Dereference in the appid.sys driver

★ 2 · 2024-05-05
hackyboiz/kcfg-bypass

kcfg bypass example - CVE-2024-21338

★ 2 · 2025-01-12
CVE-2026-94545
MULTI PoC
CVSS 5.3 MEDIUM CWE-116 Published 2026-09-30 PoCs 5 ★ 49 Last push 2026-09-30 (1 week, 2 days ago)

Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.

Show 5 repositories
EQSTLab/CVE-2026-94545

Next.js RCE

★ 49 · 2026-09-29
mhtsec/CVE-2026-94545

Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC

★ 2 · 2026-09-30
HORKimhab/CVE-2026-94545

CVE-2026-94545 - Draft or TODO

★ 1 · 2026-09-23
Hassham1/CVE-2026-94545-nextjs-og-poc

CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerabl…

★ 1 · 2026-09-23
MRdark-ops/CVE-2026-94545-

Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC

★ 1 · 2026-09-30
CVE-2023-20198
MULTI PoC
PoCs 35 ★ 66 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 35 repositories
smokeintheshell/CVE-2023-20198

CVE-2023-20198 Exploit PoC

★ 66 · 2026-03-26
W01fh4cker/CVE-2023-20198-RCE

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.

★ 43 · 2024-04-25
fox-it/cisco-ios-xe-implant-detection

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

★ 41 · 2026-09-30
Shadow0ps/CVE-2023-20198-Scanner

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

★ 33 · 2023-10-24
ZephrFish/CVE-2023-20198-Checker

CVE-2023-20198 & 0Day Implant Scanner

★ 32 · 2026-07-30
Atea-Redteam/CVE-2023-20198

CVE-2023-20198 Checkscript

★ 20 · 2023-10-23
Tounsi007/CVE-2023-20198

CVE-2023-20198 PoC (!)

★ 11 · 2023-10-17
Pushkarup/CVE-2023-20198

A PoC for CVE 2023-20198

★ 8 · 2023-10-23
CVE-2026-33017
MULTI PoC
PoCs 27 ★ 11 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 27 repositories
EQSTLab/CVE-2026-33017

Langflow RCE

★ 11 · 2026-08-19
MaxMnMl/langflow-CVE-2026-33017-poc

CVE-2026-33017 - An unauthenticated remote code execution in Langflow <= 1.8.1 via Public Flow Build Endpoint

★ 10 · 2026-03-22
z4yd3/PoC-CVE-2026-33017

CVE-2026-33017: Unauthenticated RCE in Langflow

★ 5 · 2026-03-27
c0gnit00/CVE-2026-33017

Python POC, Exploit for CVE-2026-33017

★ 2 · 2026-07-02
CerberusMrXi/Langflow-cve-2026-33017-exploit

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated testing. Validate…

★ 2 · 2026-07-19
omer-efe-curkus/CVE-2026-33017-Langflow-RCE-PoC

The vulnerability in Langflow 1.8.1 and earlier allows a remote, unauthenticated attacker to achieve arbitrary command execution on the host.

★ 1 · 2026-03-21
Jorrit-VM/CVE-2026-33017
★ 1 · 2026-05-07
Industri4l-H3ll-Xpl0it3rs/CVE-2026-33017-Langflow-RCE

CVE-2026-33017 Exploit | by infrar3d

★ 1 · 2026-07-17
CVE-2025-31161
MULTI PoC
PoCs 20 ★ 48 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 20 repositories
Immersive-Labs-Sec/CVE-2025-31161

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

★ 48 · 2025-04-08
0xgh057r3c0n/CVE-2025-31161

🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit

★ 5 · 2025-05-23
TX-One/CVE-2025-31161

CrushFTP CVE-2025-31161 Exploit Tool 🔓

★ 2 · 2025-04-22
f4dee-backup/CVE-2025-31161

PoC CVE-2025-31161 - Authentication Bypass CrushFTP

★ 2 · 2025-09-14
SUPRAAA-1337/Nuclei_CVE-2025-31161_CVE-2025-2825

Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)

★ 1 · 2025-04-24
cesarbtakeda/CVE-2025-31161
★ 1 · 2025-10-21
ch3m1cl/CVE-2025-31161
★ 1 · 2025-12-07
Dairrow/CVE-2025-31161

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

★ 1 · 2026-01-11
CVE-2026-16723
HOTMULTI PoC
PoCs 11 ★ 206 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
dinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attack…

★ 206 · 2026-07-27
why-success/fastjson-rce-lab

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

★ 4 · 2026-07-28
1xPwn/CVE-2026-16723

A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.

★ 2 · 2026-09-30
HORKimhab/CVE-2026-16723

CVE-2026-16723

★ 1 · 2026-07-26
EQSTLab/CVE-2026-16723

Fastjson RCE

★ 1 · 2026-07-30
fazilbaig1/CVE-2026-16723

This is N-day patch we releasing by testing our model capabilities

★ 1 · 2026-07-31
Superman-L/CVE-2026-16723

fastjson jsontype利用

★ 1 · 2026-08-19
CVE-2025-30208
HOTMULTI PoC
PoCs 24 ★ 194 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
ThumpBo/CVE-2025-30208-EXP

CVE-2025-30208-EXP

★ 194 · 2025-04-01
xuemian168/CVE-2025-30208

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

★ 49 · 2025-04-13
4xura/CVE-2025-30208

A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).

★ 12 · 2025-04-09
marino-admin/Vite-CVE-2025-30208-Scanner

CVE-2025-30208-EXP 任意文件读取

★ 10 · 2025-03-27
ThemeHackers/CVE-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

★ 10 · 2025-06-29
jackieya/ViteVulScan

针对CVE-2025-30208和CVE-2025-31125的漏洞利用

★ 7 · 2025-04-10
4m3rr0r/CVE-2025-30208-PoC

CVE-2025-30208 - Vite Arbitrary File Read PoC

★ 7 · 2025-09-08
CVE-2020-24186
MULTI PoC
PoCs 7 ★ 19 Last push 2026-09-29 (1 week, 3 days ago)

Fetching description from NVD…

Show 7 repositories
hev0x/CVE-2020-24186-wpDiscuz-7.0.4-RCE

wpDiscuz 7.0.4 Remote Code Execution

★ 19 · 2021-06-15
Sakura-501/CVE-2020-24186-exploit

CVE-2020-24186的攻击脚本

★ 3 · 2022-04-05
meicookies/CVE-2020-24186

WpDiscuz 7.0.4 Arbitrary File Upload Exploit

★ 0 · 2021-08-13
GazettEl/CVE-2020-24186
★ 0 · 2025-03-12
sec-dojo-com/CVE-2020-24186
★ 0 · 2025-11-29
kiyingiericmark-wq/CVE-2020-24186
★ 0 · 2026-09-29
CVE-2026-34990
MULTI PoC
PoCs 12 ★ 31 Last push 2026-09-29 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 12 repositories
predyy/CVE-2026-34990

CVE-2026-34990 minimal PoC. CUPS <= 2.4.16 local privesc.

★ 31 · 2026-09-27
0xc4rc3l/CVE-2026-34990-poc
★ 3 · 2026-09-27
Noorkhalel/CVE-2026-34990-CUPS-LPE-PoC

Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.

★ 3 · 2026-09-28
khush-613/CVE-2026-34990-poc
★ 2 · 2026-09-27
DENNISDGR/CVE-2026-34990-poc

LPE PoC for CVE-2026-34990 using a CUPS root file write vulnerability.

★ 1 · 2026-09-27
ungabunga-ctf/CVE-2026-34990

CVE-2026-34990 - OpenPrinting CUPS versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhos…

★ 1 · 2026-09-28
HORKimhab/CVE-2026-34990

CVE-2026-34990 - Draft or Todo

★ 0 · 2026-08-06
TRX-0/CVE-2026-34990-cups-lpe
★ 0 · 2026-09-21
CVE-2026-54121
HOTMULTI PoC
PoCs 14 ★ 332 Last push 2026-09-29 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
aniqfakhrul/CVE-2026-54121

Certighost POC

★ 332 · 2026-07-28
ZeroDayEvil/CVE-2026-54121-Certighost

🛡️ Official AI Security Tool module for CVE-2026-54121 (Certighost - AD CS Domain Controller Impersonation & PKINIT Elevation).

★ 88 · 2026-09-12
tc4dy/CVE-2026-54121-PoC-Exploit

CVE-2026-54121 - CertiGhost AD CS Multi-Exploit Framework | Rogue DC + LDAP spoofing, certificate abuse, PKINIT hash extraction, auto DCSync. Safe Checker + fu…

★ 30 · 2026-09-29
ZeroDayEvil/CVE-2026-54121
★ 26 · 2026-09-28
marcgoam/CVE-2026-54121-CertiGhost

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

★ 11 · 2026-07-27
nafiez/Metasploit-CVE-2026-54121-Certighost

A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. T…

★ 4 · 2026-07-31
0xBlackash/CVE-2026-54121

CVE-2026-54121

★ 2 · 2026-07-25
ChPratik/CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

★ 1 · 2026-07-28
< Prev Page 7 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.