Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
14 contacts in last 24h
11117CVEs tracked
26011PoC repositories
20New in 24h
357PoC updated in 7 days
filters
803 results
PoCs 6
★ 28
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 6 repositories
remmons-r7/rapid7-CVE-2026-15409
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlan…
★ 28 · 2026-07-15
tc4dy/CVE-2026-15409-15410-Framework
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework - SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --prives…
★ 5 · 2026-09-29
Ch4120N/CVE-2026-15409
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as …
★ 3 · 2026-08-03
PoCs 32
★ 688
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 32 repositories
ThemeHackers/CVE-2024-38063
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
★ 44 · 2025-12-10
PoCs 34
★ 73
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 34 repositories
hexsecteam/CVE-2025-8088-Winrar-Tool
A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header man…
★ 50 · 2025-09-04
jordan922/CVE-2025-8088
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
★ 10 · 2025-08-11
PoCs 13
★ 7
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 13 repositories
pawpic/CVE-2026-38526-POC
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution
★ 1 · 2026-06-26
PoCs 12
★ 125
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 12 repositories
dinosn/pack2theroot-lab
CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation
★ 8 · 2026-04-25
PoCs 5
★ 105
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 5 repositories
e4zyy/Project-CVE-2026-75604
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilitie…
★ 3 · 2026-08-27
HackSpeak/CVE-2026-75604
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
★ 2 · 2026-08-26
FORTBRIDGE-UK/cve-2026-75604
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
★ 0 · 2026-09-05
PoCs 7
★ 261
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 7 repositories
orinimron123/CVE-2026-40369-EXPLOIT
Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandb…
★ 261 · 2026-05-18
dbgbgtf1/cve-2026-40369-exploit
Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges
★ 0 · 2026-09-08
PoCs 16
★ 18
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 16 repositories
PoCs 5
★ 96
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 5 repositories
securekomodo/citrixInspector
Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…
★ 96 · 2026-09-28
PoCs 13
★ 228
Last push 2026-09-28 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 13 repositories
securekomodo/citrixInspector
Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…
★ 96 · 2026-09-28
PoCs 6
★ 0
Last push 2026-09-28 (1 week, 5 days ago)
Fetching description from NVD…
Show 6 repositories
PoCs 27
★ 25
Last push 2026-09-28 (1 week, 5 days ago)
Fetching description from NVD…
Show 8 of 27 repositories
str1keboo/CVE-2025-49132
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.
★ 4 · 2026-02-08
PoCs 10
★ 21
Last push 2026-09-26 (1 week, 6 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
Debajyoti0-0/CVE-2026-64600
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability…
★ 7 · 2026-07-26
vulnquest58/VQ-RefluxCore
is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level …
★ 0 · 2026-07-24
PoCs 14
★ 146
Last push 2026-09-26 (1 week, 6 days ago)
Fetching description from NVD…
Show 8 of 14 repositories
vulnquest58/dirtyclone-exploit
CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9
★ 7 · 2026-06-28
PoCs 8
★ 7
Last push 2026-09-26 (2 weeks ago)
Fetching description from NVD…
Show 8 repositories
NiteeshPujari/CVE-2024-37054-MLflow-RCE
NiteeshPujari/CVE-2024-37054, This repository contains a Proof of Concept (PoC) a critical deserialization vulnerability in MLflow that allows for Remote Code …
★ 3 · 2025-08-22
BardLaudian/CVE-2024-37054
Generic PoC for MLflow pickle deserialization RCE (CVE-2024-37054-style). Poisons a registered model via the MLflow REST API to achieve code execution when the…
★ 0 · 2026-09-23
PoCs 15
★ 84
Last push 2026-09-26 (2 weeks ago)
Fetching description from NVD…
Show 8 of 15 repositories
0xbinder/CVE-2026-0073
An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debug…
★ 29 · 2026-05-20
tc4dy/CVE-2026-0073-PoC-Exploit
CVE-2026-0073 – Android ADB Wireless Debugging Auth Bypass (CVSS 8.8) | Zero-click TLS type confusion to unauthenticated shell. 2 tools: Full Exploit (ADB shel…
★ 15 · 2026-09-26
unnaim/adbHijacker
A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled
★ 8 · 2026-05-07
PoCs 9
★ 34
Last push 2026-09-26 (2 weeks ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 13
★ 270
Last push 2026-09-26 (2 weeks ago)
Fetching description from NVD…
Show 8 of 13 repositories
PoCs 7
★ 197
Last push 2026-09-26 (2 weeks ago)
Fetching description from NVD…
Show 7 repositories
TheBl4ckPh4nt0m/CVE-2025-21298
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). Th…
★ 1 · 2025-03-07
PoCs 50
★ 2003
Last push 2026-09-25 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 50 repositories
calebstewart/CVE-2021-1675
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
★ 1109 · 2021-07-05
PoCs 7
★ 289
Last push 2026-09-25 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 7 repositories
dhmosfunk/CVE-2023-25690-POC
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…
★ 289 · 2024-08-24
oOCyginXOo/CVE-2023-25690-POC
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…
★ 2 · 2025-06-01
arnavps/CTF-Web-Exploitation
A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced XSS/RCE c…
★ 1 · 2026-04-05
roshanrajbanshi/cve-2023-25690-smuggler
Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe's Contrabando…
★ 0 · 2026-09-25
PoCs 5
★ 16
Last push 2026-09-24 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 5 repositories
PoCs 11
★ 2
Last push 2026-09-24 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 11 repositories
mishaqdev/cve-2010-2075-analysis
Technical writeup and penetration testing report for CVE-2010-2075, demonstrating UnrealIRCd backdoor exploitation and remediation.
★ 0 · 2026-06-18
PoCs 7
★ 61
Last push 2026-09-24 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 7 repositories
BardLaudian/CVE-2023-49070
Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc
★ 0 · 2026-09-24
PoCs 5
★ 36
Last push 2026-09-24 (2 weeks, 1 day ago)
Fetching description from NVD…
Show 5 repositories
BardLaudian/CVE-2018-9276
CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.
★ 0 · 2026-09-24
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.