Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
803 results
PoCs 6
★ 5
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 6 repositories
PoCs 5
★ 9
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 5 repositories
LucasKatashi/paint2die
Simplest and most reliable RichFaces Paint2DResource CVE-2018-12533 RF-14310 exploit PoC
★ 1 · 2025-11-25
CVSS 9.8 CRITICAL
CWE-73, CWE-94
Published 2026-09-20
PoCs 5
★ 2
Last push 2026-10-01 (1 week, 1 day ago)
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.
Show 5 repositories
murrez/CVE-2026-90817
Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation.
★ 2 · 2026-09-21
PoCs 19
★ 80
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 20
★ 37
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 20 repositories
Chocapikk/CVE-2023-28432
Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.
★ 11 · 2026-01-08
PoCs 84
★ 3551
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 84 repositories
amlweems/xzbot
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
★ 3551 · 2024-04-03
PoCs 58
★ 195
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…
★ 195 · 2025-03-14
x00byte/PutScanner
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
★ 9 · 2025-07-19
PoCs 25
★ 339
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 25 repositories
peterpt/eternal_scanner
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
★ 339 · 2024-07-31
AtithKhawas/autoblue
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …
★ 5 · 2024-12-30
sethwhy/BlueDoor
Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…
★ 2 · 2024-12-22
PoCs 30
★ 2
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 30 repositories
mk017-hk/CVE-2025-5548
Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulner…
★ 2 · 2026-05-08
TheMalwareGuardian/CVE-2025-5548
Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.
★ 1 · 2026-03-23
JSantos1990/CVE-2025-5548
🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation, lab enviro…
★ 0 · 2026-03-18
PoCs 20
★ 31
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 20 repositories
kayl22/cve-2025-8110-GOGS-RCE
GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then trigge…
★ 4 · 2026-04-11
3jee/CVE-2025-8110
CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API
★ 2 · 2026-04-11
PoCs 6
★ 10
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 6 repositories
PoCs 7
★ 3
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 7 repositories
Ch4120N/CVE-2026-58138
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
★ 2 · 2026-07-15
PoCs 7
★ 9
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 7 repositories
isagoakira/ghes-cve-scanner
GHES CVE Scanner — Defensive security tool for detecting CVE-2026-3854 (Git Push RCE) and CVE-2026-4821 (Management Console proxy injection) in GitHub …
★ 0 · 2026-05-05
PoCs 60
★ 783
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 60 repositories
ignis-sec/CVE-2023-38831-RaRCE
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
★ 113 · 2023-08-27
xaitax/WinRAR-CVE-2023-38831
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …
★ 17 · 2023-09-08
PoCs 13
★ 1
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 13 repositories
maradonam18/-CVE-2025-59528-PoC
A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also used in HTB s…
★ 1 · 2026-04-15
arensballiu/Flowise-RCE-CVE-2025-59528
Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the /api/v1/node-load-method/customMCP endpoint…
★ 1 · 2026-09-28
NymiiTechTips/CVE-2025-59528
Technical PoC for CVE-2025-59528 (Flowise < 3.0.5), demonstrating authenticated RCE through customMCP mcpServerConfig injection, with clear bilingual documenta…
★ 1 · 2026-05-16
PoCs 9
★ 332
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 9 repositories
hakaioffsec/CVE-2024-21338
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
★ 332 · 2024-04-16
CVSS 5.3 MEDIUM
CWE-116
Published 2026-09-30
PoCs 5
★ 49
Last push 2026-09-30 (1 week, 2 days ago)
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
Show 5 repositories
Hassham1/CVE-2026-94545-nextjs-og-poc
CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerabl…
★ 1 · 2026-09-23
PoCs 35
★ 66
Last push 2026-09-30 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 35 repositories
Shadow0ps/CVE-2023-20198-Scanner
This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273
★ 33 · 2023-10-24
PoCs 27
★ 11
Last push 2026-09-30 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 27 repositories
PoCs 20
★ 48
Last push 2026-09-30 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 20 repositories
PoCs 11
★ 206
Last push 2026-09-30 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 11 repositories
dinosn/fastjson-jsontype-rce-lab
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attack…
★ 206 · 2026-07-27
PoCs 24
★ 194
Last push 2026-09-30 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 24 repositories
4xura/CVE-2025-30208
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
★ 12 · 2025-04-09
ThemeHackers/CVE-2025-30208
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
★ 10 · 2025-06-29
PoCs 7
★ 19
Last push 2026-09-29 (1 week, 3 days ago)
Fetching description from NVD…
Show 7 repositories
PoCs 12
★ 31
Last push 2026-09-29 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 12 repositories
ungabunga-ctf/CVE-2026-34990
CVE-2026-34990 - OpenPrinting CUPS versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhos…
★ 1 · 2026-09-28
PoCs 14
★ 332
Last push 2026-09-29 (1 week, 3 days ago)
Fetching description from NVD…
Show 8 of 14 repositories
tc4dy/CVE-2026-54121-PoC-Exploit
CVE-2026-54121 - CertiGhost AD CS Multi-Exploit Framework | Rogue DC + LDAP spoofing, certificate abuse, PKINIT hash extraction, auto DCSync. Safe Checker + fu…
★ 30 · 2026-09-29
ChPratik/CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
★ 1 · 2026-07-28
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.