Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
352PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

803 results

CVE-2025-24071
HOTMULTI PoC
PoCs 23 ★ 409 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 23 repositories
0x6rss/CVE-2025-24071_PoC

CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

★ 409 · 2025-03-20
ThemeHackers/CVE-2025-24071

Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)

★ 34 · 2025-03-27
FOLKS-iwd/CVE-2025-24071-msfvenom

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

★ 25 · 2025-03-18
Marcejr117/CVE-2025-24071_PoC

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

★ 24 · 2025-05-15
ex-cal1bur/SMB_CVE-2025-24071

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without …

★ 4 · 2025-06-11
LOOKY243/CVE-2025-24071-PoC

CVE-2025-24071 Proof Of Concept

★ 3 · 2025-05-27
TH-SecForge/CVE-2025-24071

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

★ 3 · 2025-06-09
ctabango/CVE-2025-24071_PoCExtra

Alternativa CVE-2025-24071_PoC

★ 2 · 2025-08-21
CVE-2024-42327
MULTI PoC
PoCs 11 ★ 48 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
BridgerAlderson/Zabbix-CVE-2024-42327-SQL-Injection-RCE

Zabbix CVE-2024-42327 PoC

★ 48 · 2025-01-03
aramosf/cve-2024-42327

cve-2024-42327 ZBX-25623

★ 38 · 2024-12-01
compr00t/CVE-2024-42327

PoC for CVE-2024-42327 / ZBX-25623

★ 18 · 2024-12-03
godylockz/CVE-2024-42327

Proof of concept for CVE-2024-42327: Zabbix privilege escalation to RCE

★ 9 · 2026-09-24
depers-rus/CVE-2024-42327
★ 3 · 2024-12-06
watchdog1337/CVE-2024-42327_Zabbix_SQLI

POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method

★ 3 · 2024-12-08
874anthony/CVE-2024-42327_Zabbix_SQLi

This is for educational porpuses only. Please do not use agains unathorized systems.

★ 1 · 2025-04-19
RichJJ98/analise-vulnerabilidades-zabbix-notebooklm

Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque …

★ 1 · 2026-06-09
CVE-2023-40028
MULTI PoC
PoCs 10 ★ 13 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
0xyassine/CVE-2023-40028
★ 13 · 2024-03-23
0xDTC/Ghost-5.58-Arbitrary-File-Read-CVE-2023-40028

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symli…

★ 13 · 2025-01-07
monke443/CVE-2023-40028

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

★ 5 · 2024-12-21
rvzsec/CVE-2023-40028

CVE-2023-40028 PoC Exploit

★ 3 · 2024-12-28
godylockz/CVE-2023-40028

Proof of concept for CVE-2023-40028: Ghost arbitrary file read

★ 2 · 2026-09-24
Stp1t/CVE-2023-40028

Exploit for CVE-2023-40028 (for educational purposes)

★ 1 · 2026-01-29
sudlit/CVE-2023-40028
★ 0 · 2024-12-13
rehan6658/CVE-2023-40028
★ 0 · 2025-02-02
CVE-2024-23692
MULTI PoC
PoCs 14 ★ 51 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
verylazytech/CVE-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

★ 51 · 2025-03-24
jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS

Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)

★ 17 · 2024-06-13
0x20c/CVE-2024-23692-EXP

CVE-2024-23692 Exploit

★ 14 · 2024-06-18
vanboomqi/CVE-2024-23692
★ 12 · 2024-06-15
BBD-YZZ/CVE-2024-23692

CVE-2024-23692

★ 7 · 2024-06-18
NanoWraith/CVE-2024-23692
★ 4 · 2024-06-11
pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

★ 1 · 2024-07-10
NingXin2002/HFS2.3_poc

HFS2.3未经身份验证的远程代码执行(CVE-2024-23692)

★ 1 · 2024-12-21
CVE-2021-40444
HOTMULTI PoC
PoCs 34 ★ 1835 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 34 repositories
lockedbyte/CVE-2021-40444

CVE-2021-40444 PoC

★ 1835 · 2021-12-25
klezVirus/CVE-2021-40444

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

★ 836 · 2023-10-11
aslitsecurity/CVE-2021-40444_builders

This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit

★ 174 · 2021-10-11
Edubr2020/CVE-2021-40444--CABless

Modified code so that we don´t need to rely on CAB archives

★ 105 · 2021-09-22
k8gege/CVE-2021-40444
★ 21 · 2021-09-14
ozergoker/CVE-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444

★ 18 · 2021-09-29
rfcxv/CVE-2021-40444-POC
★ 18 · 2021-09-09
CVE-2025-64512
MULTI PoC
PoCs 10 ★ 8 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
luigigubello/CVE-2025-64512-Polyglot-PoC

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

★ 8 · 2026-04-10
matesz44/CVE-2025-64512

CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads

★ 4 · 2026-07-19
BardLaudian/CVE-2025-64512

CLI wrapper around the official PoC for CVE-2025-64512 — pdfminer.six insecure pickle deserialization via crafted PDF (RCE)

★ 1 · 2026-09-23
joeack123/PoC-for-CVE-2025-64512

PoC script for CVE-2025-64512

★ 0 · 2026-07-19
MehdiChyhab/CVE-2025-64512-exploit

CVE-2025-64512 - pdfminer.six Remote Code Execution Exploit

★ 0 · 2026-07-21
stoic-crawler/CVE-2025-64512

Exploit for CVE-2025-64512 to get a reverse shell.

★ 0 · 2026-07-22
DodgeNefoli/CVE-2025-64512
★ 0 · 2026-08-12
CVE-2025-22457
MULTI PoC
PoCs 6 ★ 73 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 6 repositories
sfewer-r7/CVE-2025-22457

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and …

★ 73 · 2025-04-25
securekomodo/CVE-2025-22457

CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE

★ 18 · 2025-04-17
Vinylrider/ivantiunlocker

Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN

★ 2 · 2025-04-13
TRone-ux/CVE-2025-22457

PoC CVE-2025-22457

★ 1 · 2025-05-25
benmevic/cve-2025-22457

Altay takımı haftalık sunumu için yaptığım cve-2025-22457 zafiyeti demo uygulaması

★ 0 · 2026-07-10
CVE-2026-5118
MULTI PoC
PoCs 6 ★ 5 Last push 2026-09-22 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 6 repositories
zycoder0day/CVE-2026-5118

CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection

★ 5 · 2026-05-21
puj790201-lab/CVE-2026-5118

CVE-2026-5118-exp_wordpress_Divi Form Builder

★ 1 · 2026-05-21
Jenderal92/CVE-2026-5118

CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce…

★ 0 · 2026-05-30
Yucaerin/CVE-2026-5118

Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection

★ 0 · 2026-05-22
1beelze/CVE-2026-5118
★ 0 · 2026-07-13
SangSenimanWartefak/CVE-2026-5118
★ 0 · 2026-09-22
CVE-2025-23266
MULTI PoC
PoCs 5 ★ 15 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 5 repositories
jpts/cve-2025-23266-poc

PoC for NVIDIAScape bug

★ 15 · 2025-07-19
r0binak/CVE-2025-23266

CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit

★ 1 · 2026-03-19
Mindasy/cve-2025-23266-migration-bypass

cve-2025-23266-migration-bypass

★ 1 · 2025-09-04
mrk336/CVE-2025-23266

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains…

★ 1 · 2025-09-07
CR1MS0N-Operator/security-research

Original offensive security research into Linux container boundary weaknesses. Whitepaper 1: OCI hook isolation failures in the NVIDIA Container Toolkit (CVE-2…

★ 0 · 2026-09-22
CVE-2025-36911
HOTMULTI PoC
PoCs 10 ★ 857 Last push 2026-09-21 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
zalexdev/wpair-app

WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This vulnerabil…

★ 857 · 2026-01-18
SpectrixDev/DIY_WhisperPair

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

★ 107 · 2026-05-28
KULeuven-COSIC/WhisperPair

The official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol.

★ 105 · 2026-09-21
Ymsniper/Whisper_Bully

Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)

★ 39 · 2026-07-13
PentHertz/CVE-2025-36911-exploit

Exploit of the CVE-2025-36911 vulnerability in Python for testing our own equipment

★ 27 · 2026-01-28
PivotChip/FrostedFastPair

WhisperPair (CVE-2025-36911) POC for ESP32 device

★ 15 · 2026-01-31
aalex954/whisperpair-poc-tool

A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability

★ 8 · 2026-01-25
Cedric-Martz/CVE-2025-36911_scan

This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.

★ 3 · 2026-01-17
CVE-2026-33634
MULTI PoC
PoCs 5 ★ 12 Last push 2026-09-21 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 5 repositories
ugurrates/teampcp-supply-chain-attack

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

★ 12 · 2026-07-28
fevar54/CVE-2026-33634-Scanner

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

★ 0 · 2026-03-30
AshleyT3/docker-socket-risk-demos

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

★ 0 · 2026-03-31
dfs333/trivysupplychainanalysis

Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM proba…

★ 0 · 2026-07-16
joaovicdev/EXPLOIT-CVE-2026-33634
★ 0 · 2026-09-21
CVE-2023-21716
MULTI PoC
PoCs 12 ★ 59 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 12 repositories
gyaansastra/CVE-2023-21716

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF …

★ 59 · 2026-09-21
Xnuvers007/CVE-2023-21716

RTF Crash POC Python 3.11 Windows 10

★ 46 · 2023-03-07
JMousqueton/CVE-2023-21716

POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption

★ 8 · 2023-04-16
hv0l/CVE-2023-21716_exploit

test of exploit for CVE-2023-21716

★ 6 · 2023-03-24
FeatherStark/CVE-2023-21716
★ 4 · 2023-03-07
RonF98/CVE-2023-21716-POC

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption

★ 4 · 2025-07-07
MojithaR/CVE-2023-21716-EXPLOIT.py

This is an exploit file which is used to check CVE-2021-21716 vulnerability

★ 3 · 2023-11-05
mikesxrs/CVE-2023-21716_YARA_Results

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

★ 0 · 2023-03-11
CVE-2022-38694
HOTMULTI PoC
PoCs 15 ★ 624 Last push 2026-09-20 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 15 repositories
TomKing062/CVE-2022-38694_unlock_bootloader

This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692

★ 624 · 2025-06-14
TheGammaSqueeze/Bootloader_Unlock_Anbernic_T820

Bootloader unlock using CVE-2022-38694 for Anbernic Unisoc T820 devices

★ 65 · 2025-09-19
LeoChen-CoreMind/spd_flasher

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices

★ 8 · 2026-08-05
AureliusIvan/ubl-itel-s23

Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694

★ 7 · 2026-03-04
Phlegmelm/CRACK12

rooting an ATOZEE P12 on Android 14 using CVE-2022-38694 — because fastboot oem unlock said no, so we found another way.

★ 5 · 2026-05-14
mutur4/UnisocBootROMs

This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694

★ 5 · 2026-08-11
Gopartner/realme-c53-unlock-root

Bootloader unlock (CVE-2022-38694) & root guide for Realme C53 / RMX3760 (Unisoc T612)

★ 3 · 2026-08-07
JoshAtticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

★ 3 · 2026-06-03
CVE-2023-27163
MULTI PoC
PoCs 24 ★ 32 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
entr0pie/CVE-2023-27163

Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)

★ 32 · 2023-08-09
samh4cks/CVE-2023-27163-InternalProber

A tool to perform port scanning using vulnerable Request-Baskets

★ 5 · 2023-08-28
seanrdev/cve-2023-27163

To assist in enumerating the webserver behind the webserver SSRF CVE-2023-27163

★ 4 · 2023-07-22
hhesenjan/CVE-2023-27163-AND-Mailtrail-v0.53

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53

★ 2 · 2023-08-05
rvzsec/CVE-2023-27163

CVE-2023-27163 - Request Baskets SSRF

★ 2 · 2023-08-09
thomas-osgood/CVE-2023-27163

Golang PoC for CVE-2023-27163 Mailtrail Exploit

★ 2 · 2023-08-14
MasterCode112/CVE-2023-27163

Proof of Concept for Server Side Request Forgery (SSRF) in request-baskets (V<= v.1.2.1)

★ 2 · 2024-01-10
lukehebe/CVE-2023-27163-POC

CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerab…

★ 2 · 2025-04-18
CVE-2023-21554
MULTI PoC
PoCs 6 ★ 60 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 6 repositories
zoemurmure/CVE-2023-21554-PoC

CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/

★ 60 · 2023-05-18
3tternp/CVE-2023-21554
★ 28 · 2023-08-21
leongxudong/MSMQ-Vulnerability

Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability

★ 5 · 2026-06-29
shootweb/CVE-2023-21554

CVE-2023-21554 PoC

★ 2 · 2025-10-09
Rahul-Thakur7/CVE-2023-21554
★ 0 · 2024-12-16
TheArtist54/CVE-2023-21554-PoC
★ 0 · 2026-09-20
CVE-2026-23111
MULTI PoC
PoCs 10 ★ 9 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
Knz-source/CVE-2026-23111-POC-noddlenpottato

CVE-2026-23111 nf_tables catchall UAF — unprivileged LPE for Linux 5.10-6.18. Auto-adaptive exploit with KASLR bypass, arbitrary kernel read, and ROP chain. Su…

★ 9 · 2026-08-12
Baba01hacker666/CVE-2026-23111

Linux Kernel nf_tables Use-After-Free (CVE-2026-23111) — LPE PoC

★ 7 · 2026-07-10
0xBlackash/CVE-2026-23111

CVE-2026-23111

★ 4 · 2026-06-09
ishankaru/CVE-2026-23111-nftables-lab

Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection, mitigation, m…

★ 2 · 2026-06-11
bakano98/cve-2026-23111-poc

scuffed PoC for CVE-2026-23111. Made and ran on Linux Kernel 6.12.69

★ 1 · 2026-07-01
vrtlbob/Linux-Kernel-Vulnerabilities-CVE-2026-23111

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break out of th…

★ 1 · 2026-07-02
HORKimhab/CVE-2026-23111

CVE-2026-23111 - Linux - Draft

★ 0 · 2026-06-09
criann/check-cve-2026-23111

Script to check if system are vulnable to cve-2026-23111

★ 0 · 2026-06-11
CVE-2025-32433
HOTMULTI PoC
PoCs 41 ★ 142 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 8 of 41 repositories
ProDefense/CVE-2025-32433

CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

★ 142 · 2025-08-02
omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

★ 16 · 2025-08-04
NiteeshPujari/CVE-2025-32433-PoC

CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433

★ 7 · 2025-08-14
m0usem0use/erl_mouse

python script to find vulnerable targets of CVE-2025-32433

★ 6 · 2025-04-19
0xPThree/cve-2025-32433
★ 6 · 2025-04-19
ekomsSavior/POC_CVE-2025-32433
★ 4 · 2025-04-19
darses/CVE-2025-32433

Security research on Erlang/OTP SSH CVE-2025-32433.

★ 3 · 2025-04-19
LemieOne/CVE-2025-32433

Missing Authentication for Critical Function (CWE-306)-Exploit

★ 3 · 2025-04-18
CVE-2020-0688
HOTMULTI PoC
PoCs 24 ★ 353 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 24 repositories
zcgonvh/CVE-2020-0688

Exploit and detect tools for CVE-2020-0688

★ 353 · 2020-03-21
Ridter/cve-2020-0688

cve-2020-0688

★ 327 · 2023-07-04
random-robbie/cve-2020-0688

cve-2020-0688

★ 165 · 2020-02-26
Yt1g3r/CVE-2020-0688_EXP

CVE-2020-0688_EXP Auto trigger payload & encrypt method

★ 144 · 2020-02-27
Jumbo-WJB/CVE-2020-0688

CVE-2020-0688 - Exchange

★ 66 · 2020-02-27
onSec-fr/CVE-2020-0688-Scanner

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.

★ 37 · 2026-09-18
w4fz5uck5/cve-2020-0688-webshell-upload-technique

cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output

★ 23 · 2023-09-12
MrTiz/CVE-2020-0688

Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys

★ 22 · 2021-06-06
CVE-2009-3103
MULTI PoC
PoCs 6 ★ 4 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 6 repositories
Sic4rio/CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050-

Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)

★ 4 · 2024-05-05
sooklalad/ms09050

cve-2009-3103

★ 1 · 2017-01-17
sec13b/ms09-050_CVE-2009-3103

CVE-2009-3103 ms09-050

★ 0 · 2024-05-03
afifudinmtop/CVE-2009-3103
★ 0 · 2026-01-26
bytejmp/MS09-050

MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow exploit with built-in scanner, arch auto-detection, and standalone reverse shell payloads for x86/x64. …

★ 0 · 2026-09-18
CVE-2021-3156
HOTMULTI PoC
PoCs 88 ★ 1025 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 88 repositories
blasty/CVE-2021-3156
★ 1025 · 2021-02-02
worawit/CVE-2021-3156

Sudo Baron Samedit Exploit

★ 807 · 2022-01-13
stong/CVE-2021-3156

PoC for CVE-2021-3156 (sudo heap overflow)

★ 428 · 2022-04-14
LiveOverflow/pwnedit

CVE-2021-3156 - Sudo Baron Samedit

★ 227 · 2022-02-12
Rvn0xsy/CVE-2021-3156-plus

CVE-2021-3156非交互式执行命令

★ 203 · 2021-02-09
CptGibbon/CVE-2021-3156

Root shell PoC for CVE-2021-3156

★ 158 · 2022-02-13
reverse-ex/CVE-2021-3156

CVE-2021-3156

★ 112 · 2021-01-31
0x4ndy/clif

clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and …

★ 100 · 2022-12-22
CVE-2025-8061
HOTMULTI PoC
PoCs 5 ★ 125 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 5 repositories
symeonp/Lenovo-CVE-2025-8061

PoC for popping a system shell against the LnvMSRIO.sys driver

★ 125 · 2025-10-06
spawn451/CVE-2025-8061-Exploit

Exploit LnvMSRIO.sys vulnerable driver

★ 18 · 2025-12-10
segura2010/lenovo-dispatcher-poc

PoC to exploit lenovo dispatcher driver (LnvMSRIO.sys) (CVE-2025-8061)

★ 4 · 2025-11-17
uLl0a/MSRMapper

MSRMapper is a manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in the vulnerable Lenovo driver LnvMSRIO.sys to perform a BYOVD (Bring You…

★ 2 · 2026-09-17
vxqs/Lenovo-CVE-2025-8061

My PoC of Lenovo-CVE-2025-8061

★ 0 · 2026-04-26
CVE-2025-32432
MULTI PoC
PoCs 14 ★ 26 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
Sachinart/CVE-2025-32432

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCM…

★ 26 · 2025-04-27
Chocapikk/CVE-2025-32432

CraftCMS RCE Checker (CVE-2025-32432)

★ 10 · 2025-04-27
CTY-Research-1/CVE-2025-32432-PoC
★ 7 · 2025-08-29
P34NUT2/CVE-2025-32432-exploit-by-P34NUT

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

★ 7 · 2026-09-17
c0gnit00/CVE-2025-32432

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

★ 4 · 2026-07-21
bambooqj/CVE-2025-32432

AI修复生成的CVE-2025-32432的poc

★ 2 · 2025-09-23
cd-ratel/CVE-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

★ 2 · 2026-05-15
PsyGuy007-sys/craftcms-cve-2025-32432-rce

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

★ 1 · 2026-08-05
CVE-2019-11447
MULTI PoC
PoCs 7 ★ 9 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 7 repositories
thewhiteh4t/cve-2019-11447

CutePHP Cute News 2.1.2 RCE PoC

★ 9 · 2021-03-18
khuntor/CVE-2019-11447-EXP

CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability

★ 1 · 2020-10-30
CRFSlick/CVE-2019-11447-POC

CuteNews 2.1.2 - CVE-2019-11447 Proof-Of-Concept

★ 1 · 2024-02-11
mt-code/CVE-2019-11447

Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.

★ 0 · 2020-10-20
ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE

Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)

★ 0 · 2021-03-17
capivara-research/WordPress-Path-Traversal-CVE-2019-11447

CPTS HackTheBox - Penetration Test Report: WordPress Path Traversal CVE-2019-11447

★ 0 · 2026-09-17
CVE-2021-29447
MULTI PoC
PoCs 24 ★ 44 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
motikan2010/CVE-2021-29447

WordPress - Authenticated XXE (CVE-2021-29447)

★ 44 · 2021-10-04
mega8bit/exploit_cve-2021-29447
★ 7 · 2022-11-27
0xRar/CVE-2021-29447-PoC

A proof of concept exploit for a wordpress 5.6 media library vulnerability

★ 6 · 2023-01-31
Vulnmachines/wordpress_cve-2021-29447

WordPress XXE vulnerability

★ 4 · 2021-05-23
M3l0nPan/wordpress-cve-2021-29447

Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.

★ 4 · 2022-11-11
dnr6419/CVE-2021-29447

Wordpress XXE injection 구축 자동화 및 PoC

★ 3 · 2022-01-10
elf1337/blind-xxe-controller-CVE-2021-29447

Arbitrary file read controller based on CVE-2021-29447

★ 3 · 2022-11-11
thomas-osgood/CVE-2021-29447

A Golang program to automate the execution of CVE-2021-29447

★ 3 · 2023-03-28
CVE-2026-49975
MULTI PoC
PoCs 14 ★ 29 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
mrx-arafat/CVE-2026-49975-POC

HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)

★ 29 · 2026-06-04
EQSTLab/CVE-2026-49975

HTTP/2 Bomb

★ 14 · 2026-06-25
fevar54/Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-

PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.

★ 6 · 2026-06-03
LSG-PolarBear/CVE-2026-49975

CVE-2026-49975漏洞复现

★ 6 · 2026-06-11
obrige/http2-bomb

CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console

★ 4 · 2026-06-05
LiaoZiqi-GZFLS/CVE-2026-49975

CVE-2026-49975

★ 3 · 2026-06-10
naheeju/POC-CVE-2026-49975

Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2

★ 3 · 2026-09-16
renzi25031469/CVE-2026-49975-HTTP-2-Bomb

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust se…

★ 2 · 2026-06-08
< Prev Page 9 / 33 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.