Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
20New in 24h
357PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2026-15409
MULTI PoC
PoCs 6 ★ 28 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 6 repositories
remmons-r7/rapid7-CVE-2026-15409

This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlan…

★ 28 · 2026-07-15
tc4dy/CVE-2026-15409-15410-Framework

CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework - SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --prives…

★ 5 · 2026-09-29
0xBlackash/CVE-2026-15409

CVE-2026-15409

★ 3 · 2026-07-15
Ch4120N/CVE-2026-15409

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as …

★ 3 · 2026-08-03
HORKimhab/CVE-2026-15409

CVE-2026-15409 - Dectect

★ 0 · 2026-07-15
MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

★ 0 · 2026-07-16
CVE-2024-38063
HOTMULTI PoC
PoCs 32 ★ 688 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 32 repositories
ynwarcs/CVE-2024-38063

poc for CVE-2024-38063 (RCE in tcpip.sys)

★ 688 · 2024-08-27
Sachinart/CVE-2024-38063-poc

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

★ 86 · 2024-08-28
ThemeHackers/CVE-2024-38063

CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)

★ 44 · 2025-12-10
patchpoint/CVE-2024-38063
★ 20 · 2024-08-27
diegoalbuquerque/CVE-2024-38063

mitigation script by disabling ipv6 of all interfaces

★ 13 · 2024-08-15
zenzue/CVE-2024-38063-POC

potential memory corruption vulnerabilities in IPv6 networks.

★ 7 · 2024-08-28
PumpkinBridge/Windows-CVE-2024-38063

Windows TCP/IP IPv6(CVE-2024-38063)

★ 4 · 2024-08-28
thanawee321/CVE-2024-38063

Vulnerability CVE-2024-38063

★ 3 · 2024-10-18
CVE-2025-8088
MULTI PoC
PoCs 34 ★ 73 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 34 repositories
sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

★ 73 · 2025-08-13
onlytoxi/CVE-2025-8088-Winrar-Tool

Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088

★ 55 · 2025-08-18
hexsecteam/CVE-2025-8088-Winrar-Tool

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header man…

★ 50 · 2025-09-04
knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

WinRAR 0day CVE-2025-8088 PoC RAR Archive

★ 44 · 2025-08-12
pentestfunctions/CVE-2025-8088-Multi-Document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

★ 35 · 2025-08-17
aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

CVE-2025-8088-BUILDER

★ 28 · 2025-10-20
AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.

★ 12 · 2025-08-26
jordan922/CVE-2025-8088

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

★ 10 · 2025-08-11
CVE-2026-38526
MULTI PoC
PoCs 13 ★ 7 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
NathanHimself/CVE-2026-38526-PoC

CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE

★ 7 · 2026-05-16
CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell ge…

★ 3 · 2026-07-14
pawpic/CVE-2026-38526-POC

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

★ 1 · 2026-06-26
Shirouuu/Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git objects. Edu…

★ 1 · 2026-09-14
mmoobbeeiidat-design/Hack-The-Box-Nexus-Findings-Report

HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and…

★ 0 · 2026-07-06
diamorphine666/CVE-2026-38526-Exploit

Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)

★ 0 · 2026-07-06
b0nyo/PoC-CVE-2026-38526

Automated exploit for Krayin CRM ≤ 2.2.x.

★ 0 · 2026-07-09
Resolvdd/CVE-2026-38526-PoC-htb-nexus

A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x

★ 0 · 2026-07-19
CVE-2026-41651
HOTMULTI PoC
PoCs 12 ★ 125 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 12 repositories
Vozec/CVE-2026-41651
★ 125 · 2026-04-23
ZeroDayEvil/CVE-2026-41651
★ 24 · 2026-09-28
baph00met/CVE-2026-41651

CVE-2026-41651 — PackageKit TOCTOU LPE

★ 17 · 2026-04-25
0xBlackash/CVE-2026-41651

CVE-2026-41651

★ 13 · 2026-04-25
shibaaa204/Pack2TheRoot

Poc for Pack2TheRoot CVE-2026-41651

★ 9 · 2026-04-29
CipherCloak/CVE-2026-41651
★ 8 · 2026-04-24
dinosn/pack2theroot-lab

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

★ 8 · 2026-04-25
Lutfifakee-Project/CVE-2026-41651

Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)

★ 5 · 2026-05-20
CVE-2026-75604
HOTMULTI PoC
PoCs 5 ★ 105 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 5 repositories
rafabd1/CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

★ 105 · 2026-08-28
ZeroDayEvil/CVE-2026-75604-PoC
★ 26 · 2026-09-28
e4zyy/Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilitie…

★ 3 · 2026-08-27
HackSpeak/CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

★ 2 · 2026-08-26
FORTBRIDGE-UK/cve-2026-75604

Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.

★ 0 · 2026-09-05
CVE-2026-40369
HOTMULTI PoC
PoCs 7 ★ 261 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 7 repositories
orinimron123/CVE-2026-40369-EXPLOIT

Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandb…

★ 261 · 2026-05-18
ZeroDayEvil/CVE-2026-40369-EXPLOIT
★ 24 · 2026-09-28
piffd0s/ntoskrnl-metadata

eprocess offset puller for relevant member offsets and function addresses for cve-2026-40369

★ 4 · 2026-05-22
0xBlackash/CVE-2026-40369

CVE-2026-40369

★ 1 · 2026-06-18
ercihan/CVE-2026-40369
★ 0 · 2026-05-22
CCELEND/CVE-2026-40369

CVE-2026-40369本地权限提升漏洞exp

★ 0 · 2026-06-23
dbgbgtf1/cve-2026-40369-exploit

Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges

★ 0 · 2026-09-08
CVE-2025-58434
MULTI PoC
PoCs 16 ★ 18 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 16 repositories
kartik2005221/CVE-2025-58434-AND-59528-POC

Combined PoC for CVE-2025-28434 and CVE-2025-59528

★ 18 · 2026-04-13
AzureADTrent/CVE-2025-58434-59528

CVE-2025-58434 and CVE-2025-59528 chain POC

★ 5 · 2026-04-12
jwsly12/CVE-2025-58434-59528-htb-ctf

Exploitation Silentium HTB-CTF

★ 2 · 2026-04-28
CVETeam/FlowiseAI-Critical-KillChain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

★ 1 · 2026-04-14
kartik2005221/CVE-2025-58434-poc
★ 1 · 2026-04-12
arensballiu/Flowise-CVE-2025-58434-PasswordReset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password without prior …

★ 1 · 2026-09-28
SteamPunk424/CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This e…

★ 1 · 2026-04-20
0xDaeras/Flowise-CVE-2025-58434-Chain-59528

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a rep…

★ 1 · 2026-05-08
CVE-2026-8452
MULTI PoC
PoCs 5 ★ 96 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 5 repositories
securekomodo/citrixInspector

Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…

★ 96 · 2026-09-28
watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

CVE-2026-8452 PreAuth RCE

★ 65 · 2026-08-14
BishopFox/CVE-2026-8452-check

Safely detect Citrix NetScaler CVE-2026-8452

★ 1 · 2026-08-20
maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, e…

★ 0 · 2026-08-30
techupdate24/citrix-netscaler-cve-2026-8452-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-27
CVE-2023-3519
HOTMULTI PoC
PoCs 13 ★ 228 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
BishopFox/CVE-2023-3519

RCE exploit for CVE-2023-3519

★ 228 · 2023-08-23
securekomodo/citrixInspector

Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…

★ 96 · 2026-09-28
telekom-security/cve-2023-3519-citrix-scanner

Citrix Scanner for CVE-2023-3519

★ 54 · 2023-07-24
mr-r3b00t/CVE-2023-3519
★ 13 · 2023-07-21
SalehLardhi/CVE-2023-3519

CVE-2023-3519 vuln for nuclei scanner

★ 11 · 2023-07-21
Chocapikk/CVE-2023-3519

Citrix ADC RCE CVE-2023-3519

★ 5 · 2026-01-08
dhammerg/CVE-2023-3519

Stack-Overflow on Citrix

★ 5 · 2024-10-06
CVE-2025-67303
MULTI PoC
PoCs 6 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 6 repositories
joker-xiaoyan/CVE-2025-67303

test

★ 0 · 2026-01-09
maybe-O/CVE-2025-67303
★ 0 · 2026-01-21
ExploreUnknowed/CVE-2025-67303
★ 0 · 2026-01-22
materaj2/exploit_cve_2025_67303

Create PoC for CVE-2025-67303

★ 0 · 2026-01-24
jcaz2378/ComfyUIrce

Git CVE-2025-67303 payload

★ 0 · 2026-05-13
Si13NTTT/CVE-2026-22777

CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303

★ 0 · 2026-09-28
CVE-2025-49132
MULTI PoC
PoCs 27 ★ 25 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 8 of 27 repositories
YoyoChaud/CVE-2025-49132

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

★ 25 · 2026-02-09
Zen-kun04/CVE-2025-49132

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

★ 17 · 2025-06-22
malw0re/CVE-2025-49132-Mods
★ 12 · 2026-02-14
63square/CVE-2025-49132

PoCs for CVE-2025-49132

★ 5 · 2025-06-24
qiaojojo/CVE-2025-49132_poc

Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓

★ 4 · 2025-06-23
str1keboo/CVE-2025-49132

This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

★ 4 · 2026-02-08
popyue/CVE-2025-49132

CVE For Pterodactyl (For Study and Education)

★ 4 · 2026-02-16
0xtensho/CVE-2025-49132-poc
★ 3 · 2026-03-13
CVE-2026-64600
MULTI PoC
PoCs 10 ★ 21 Last push 2026-09-26 (1 week, 6 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
0xBlackash/CVE-2026-64600

CVE-2026-64600

★ 21 · 2026-07-23
Debajyoti0-0/CVE-2026-64600

A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability…

★ 7 · 2026-07-26
litosmartin/CVE-2026-64600-Refluxfs-PoC

A POC for the recently discovered Qualys bug on COW with XFS

★ 4 · 2026-07-30
masrikky/CVE-2026-64600-RefluXFS

A Linux kernel local privilege escalation affecting the XFS filesystem copy-on-write (CoW) path.

★ 1 · 2026-08-08
HORKimhab/CVE-2026-64600

CVE-2026-64600 - Draft - Check todo

★ 0 · 2026-08-24
vulnquest58/VQ-RefluxCore

is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level …

★ 0 · 2026-07-24
bha-vin/CVE-2026-64600-Exploit
★ 0 · 2026-07-28
letsr00t/RefluxFS_CVE-2026-64600
★ 0 · 2026-08-04
CVE-2026-46331
HOTMULTI PoC
PoCs 14 ★ 146 Last push 2026-09-26 (1 week, 6 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
sgkdev/packet_edit_meme

PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare

★ 146 · 2026-06-17
0xBlackash/CVE-2026-46331

CVE-2026-46331

★ 34 · 2026-06-26
rjt-gupta/page-cache-corruption-lpes

CVE-2026-46331 and CVE-2026-43503

★ 12 · 2026-07-22
vulnquest58/dirtyclone-exploit

CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9

★ 7 · 2026-06-28
yanxinwu946/CVE-2026-46331

CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix

★ 5 · 2026-07-12
V0IDNETWORK/CVE-2026-46331

pedit COW

★ 1 · 2026-07-01
HORKimhab/CVE-2026-46331

CVE-2026-46331 - Draft

★ 0 · 2026-06-27
Quaerendir/cve-2026-46331-audit

cve-2026-46331-audit script

★ 0 · 2026-09-26
CVE-2024-37054
MULTI PoC
PoCs 8 ★ 7 Last push 2026-09-26 (2 weeks ago)

Fetching description from NVD…

Show 8 repositories
jimmexploit/CVE-2024-37054-PoC

PoC for CVE-2024-37054

★ 7 · 2026-05-18
ben-slates/CVE-2024-37054
★ 5 · 2026-05-17
NiteeshPujari/CVE-2024-37054-MLflow-RCE

NiteeshPujari/CVE-2024-37054, This repository contains a Proof of Concept (PoC) a critical deserialization vulnerability in MLflow that allows for Remote Code …

★ 3 · 2025-08-22
tristanqtn/CVE-2024-37054

CVE-2024-37054 exploit and documentation

★ 1 · 2026-05-19
ClearLotus-git/CVE-2024-37054-PoC
★ 0 · 2026-09-19
BardLaudian/CVE-2024-37054

Generic PoC for MLflow pickle deserialization RCE (CVE-2024-37054-style). Poisons a registered model via the MLflow REST API to achieve code execution when the…

★ 0 · 2026-09-23
0o176/CVE-2024-37054_PoC_HTB_SmartHire

MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire

★ 0 · 2026-09-26
CVE-2026-0073
MULTI PoC
PoCs 15 ★ 84 Last push 2026-09-26 (2 weeks ago)

Fetching description from NVD…

Show 8 of 15 repositories
adityatelange/poc-CVE-2026-0073

CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

★ 68 · 2026-05-06
0xbinder/CVE-2026-0073

An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debug…

★ 29 · 2026-05-20
MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC

CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using EC/Ed25519 …

★ 22 · 2026-05-07
tc4dy/CVE-2026-0073-PoC-Exploit

CVE-2026-0073 – Android ADB Wireless Debugging Auth Bypass (CVSS 8.8) | Zero-click TLS type confusion to unauthenticated shell. 2 tools: Full Exploit (ADB shel…

★ 15 · 2026-09-26
unnaim/adbHijacker

A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled

★ 8 · 2026-05-07
novaek/CVE-2026-0073-Research

CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.

★ 5 · 2026-05-06
0xBlackash/CVE-2026-0073

CVE-2026-0073

★ 5 · 2026-05-07
CVE-2026-22812
MULTI PoC
PoCs 9 ★ 34 Last push 2026-09-26 (2 weeks ago)

Fetching description from NVD…

Show 8 of 9 repositories
rohmatariow/CVE-2026-22812-exploit
★ 34 · 2026-01-16
barrersoftware/opencode-secure

Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch

★ 6 · 2026-01-19
0xgh057r3c0n/CVE-2026-22812

OpenCode < v1.0.216 - Unauthenticated RCE

★ 2 · 2026-01-19
Udyz/CVE-2026-22812-Exp

CVE-2026-22812 - OpenCode Unauth RCE

★ 1 · 2026-09-26
CayberMods/CVE-2026-22812-POC
★ 1 · 2026-01-20
HodgeLuke/ai-agent-security-research

Open security research on AI coding agent infrastructure. Agent-executable remediation manifests for CVE-2026-22812 and CVE-2026-22813.

★ 1 · 2026-03-29
0xBlackash/CVE-2026-22812

CVE-2026-22812

★ 1 · 2026-04-06
CVE-2024-49138
HOTMULTI PoC
PoCs 13 ★ 270 Last push 2026-09-26 (2 weeks ago)

Fetching description from NVD…

Show 8 of 13 repositories
MrAle98/CVE-2024-49138-POC

POC exploit for CVE-2024-49138

★ 270 · 2025-02-14
Zedocun/soc-investigation-powershell-edrfreeze

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.

★ 1 · 2026-03-09
bananoname/CVE-2024-49138-POC
★ 0 · 2025-01-21
CyprianAtsyor/letsdefend-cve-2024-49138-investigation

Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.

★ 0 · 2025-04-23
onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-Writeup

In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–491…

★ 0 · 2025-06-12
vettrivel007/CVE-2024-49138
★ 0 · 2026-04-04
CVE-2025-21298
HOTMULTI PoC
PoCs 7 ★ 197 Last push 2026-09-26 (2 weeks ago)

Fetching description from NVD…

Show 7 repositories
ynwarcs/CVE-2025-21298

Proof of concept & details for CVE-2025-21298

★ 197 · 2025-01-20
TheBl4ckPh4nt0m/CVE-2025-21298

A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). Th…

★ 1 · 2025-03-07
fy-poc/full-poc-CVE-2025_21298

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

★ 1 · 2025-09-22
tarunbharathe/Zero-Click-RCE-Incident-Response-CVE-2025-21298

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.

★ 0 · 2026-03-24
C-G-creator/LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

★ 0 · 2026-05-04
abc1230940/SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

★ 0 · 2026-05-28
mohamedbrek/SOC336-CVE-2025-21298-Investigation

LetsDefend SOC lab investigating CVE-2025-21298 Windows OLE Zero-Click RCE exploitation.

★ 0 · 2026-09-26
CVE-2021-1675
HOTMULTI PoC
PoCs 50 ★ 2003 Last push 2026-09-25 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 50 repositories
cube0x0/CVE-2021-1675

C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527

★ 2003 · 2021-07-20
calebstewart/CVE-2021-1675

Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)

★ 1109 · 2021-07-05
hlldz/CVE-2021-1675-LPE

Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527

★ 324 · 2021-07-05
ly4k/PrintNightmare

Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)

★ 215 · 2021-10-17
LaresLLC/CVE-2021-1675

CVE-2021-1675 Detection Info

★ 214 · 2023-05-20
mstxq17/CVE-2021-1675_RDL_LPE

PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。

★ 144 · 2021-09-01
sailay1996/PrintNightmare-LPE

CVE-2021-1675 (PrintNightmare)

★ 75 · 2021-07-05
evilashz/CVE-2021-1675-LPE-EXP

PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527

★ 56 · 2021-07-02
CVE-2023-25690
HOTMULTI PoC
PoCs 7 ★ 289 Last push 2026-09-25 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 7 repositories
dhmosfunk/CVE-2023-25690-POC

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…

★ 289 · 2024-08-24
thanhlam-attt/CVE-2023-25690
★ 4 · 2023-12-05
oOCyginXOo/CVE-2023-25690-POC

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…

★ 2 · 2025-06-01
tbachvarova/linux-apache-fix-mod_rewrite-spaceInURL

Fix URL containing SPACES after Apache upgrade CVE-2023-25690

★ 1 · 2023-04-25
arnavps/CTF-Web-Exploitation

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced XSS/RCE c…

★ 1 · 2026-04-05
giordy0424/CVE-2023-25690_lab

HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection

★ 0 · 2026-08-17
roshanrajbanshi/cve-2023-25690-smuggler

Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe's Contrabando…

★ 0 · 2026-09-25
CVE-2026-8461
MULTI PoC
PoCs 5 ★ 16 Last push 2026-09-24 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 5 repositories
Y5neKO/CVE-2026-8461-EXP
★ 16 · 2026-06-24
anyanything/CVE-2026-8461-PoC
★ 8 · 2026-06-23
0xBlackash/CVE-2026-8461

CVE-2026-8461

★ 5 · 2026-06-26
HORKimhab/CVE-2026-8461

CVE-2026-8461 - Draft

★ 1 · 2026-06-24
se1ims/PixelSmash

A lab setup to test cve-2026-8461

★ 0 · 2026-09-24
CVE-2010-2075
MULTI PoC
PoCs 11 ★ 2 Last push 2026-09-24 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 11 repositories
MFernstrom/OffensivePascal-CVE-2010-2075

FreePascal implementation of the UnrealIRCD CVE-2010-2075

★ 2 · 2022-05-29
FredBrave/CVE-2010-2075-UnrealIRCd-3.2.8.1

Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.

★ 1 · 2023-05-31
Tc-XoNoR/CVE-2010-2075

CVE-2010-2075 exploit

★ 1 · 2026-04-16
chancej715/UnrealIRCd-3.2.8.1-Backdoor-Command-Execution

UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).

★ 0 · 2023-04-25
JoseLRC97/UnrealIRCd-3.2.8.1-Backdoor-Command-Execution

Script that exploits the vulnerability that allows establishing a backdoor in the UnrealIRCd service with CVE-2010-2075

★ 0 · 2024-04-18
earthbendergara/unrealircd3.2.8.1-local-exploit

CVE-2010-2075

★ 0 · 2025-12-01
mishaqdev/cve-2010-2075-analysis

Technical writeup and penetration testing report for CVE-2010-2075, demonstrating UnrealIRCd backdoor exploitation and remediation.

★ 0 · 2026-06-18
Elazab2005/unrealircd-backdoor-pentest-report

Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.

★ 0 · 2026-08-20
CVE-2023-49070
MULTI PoC
PoCs 7 ★ 61 Last push 2026-09-24 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 7 repositories
D0g3-8Bit/OFBiz-Attack

A Tool For CVE-2023-49070/CVE-2023-51467 Attack

★ 18 · 2024-03-12
UserConnecting/Exploit-CVE-2023-49070-and-CVE-2023-51467-Apache-OFBiz

Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.

★ 5 · 2025-02-05
0xrobiul/CVE-2023-49070

Exploit Of Pre-auth RCE in Apache Ofbiz!!

★ 1 · 2023-12-26
yukselberkay/CVE-2023-49070_CVE-2023-51467

CVE-2023-49070 exploit and CVE-2023-49070 & CVE-2023-51467 vulnerability scanner

★ 1 · 2024-01-12
GraySignal/Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the user.

★ 1 · 2024-01-25
BardLaudian/CVE-2023-49070

Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc

★ 0 · 2026-09-24
CVE-2018-9276
MULTI PoC
PoCs 5 ★ 36 Last push 2026-09-24 (2 weeks, 1 day ago)

Fetching description from NVD…

Show 5 repositories
wildkindcc/CVE-2018-9276

CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)

★ 36 · 2020-12-03
andyfeili/CVE-2018-9276
★ 0 · 2021-01-02
alvinsmith-eroad/CVE-2018-9276

CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)

★ 0 · 2021-07-29
BardLaudian/CVE-2018-9276

CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.

★ 0 · 2026-09-24
< Prev Page 8 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.