Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
352PoC updated in 7 days
filters
803 results
PoCs 23
★ 409
Last push 2026-09-24 (2 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 23 repositories
ex-cal1bur/SMB_CVE-2025-24071
Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without …
★ 4 · 2025-06-11
PoCs 11
★ 48
Last push 2026-09-24 (2 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 11 repositories
PoCs 10
★ 13
Last push 2026-09-24 (2 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
monke443/CVE-2023-40028
Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.
★ 5 · 2024-12-21
PoCs 14
★ 51
Last push 2026-09-24 (2 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 34
★ 1835
Last push 2026-09-23 (2 weeks, 3 days ago)
Fetching description from NVD…
Show 8 of 34 repositories
PoCs 10
★ 8
Last push 2026-09-23 (2 weeks, 3 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
matesz44/CVE-2025-64512
CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads
★ 4 · 2026-07-19
BardLaudian/CVE-2025-64512
CLI wrapper around the official PoC for CVE-2025-64512 — pdfminer.six insecure pickle deserialization via crafted PDF (RCE)
★ 1 · 2026-09-23
PoCs 6
★ 73
Last push 2026-09-23 (2 weeks, 3 days ago)
Fetching description from NVD…
Show 6 repositories
sfewer-r7/CVE-2025-22457
PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and …
★ 73 · 2025-04-25
PoCs 6
★ 5
Last push 2026-09-22 (2 weeks, 3 days ago)
Fetching description from NVD…
Show 6 repositories
zycoder0day/CVE-2026-5118
CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection
★ 5 · 2026-05-21
Jenderal92/CVE-2026-5118
CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce…
★ 0 · 2026-05-30
PoCs 5
★ 15
Last push 2026-09-22 (2 weeks, 4 days ago)
Fetching description from NVD…
Show 5 repositories
mrk336/CVE-2025-23266
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains…
★ 1 · 2025-09-07
CR1MS0N-Operator/security-research
Original offensive security research into Linux container boundary weaknesses. Whitepaper 1: OCI hook isolation failures in the NVIDIA Container Toolkit (CVE-2…
★ 0 · 2026-09-22
PoCs 10
★ 857
Last push 2026-09-21 (2 weeks, 4 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
zalexdev/wpair-app
WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This vulnerabil…
★ 857 · 2026-01-18
SpectrixDev/DIY_WhisperPair
Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit
★ 107 · 2026-05-28
KULeuven-COSIC/WhisperPair
The official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol.
★ 105 · 2026-09-21
Ymsniper/Whisper_Bully
Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)
★ 39 · 2026-07-13
aalex954/whisperpair-poc-tool
A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability
★ 8 · 2026-01-25
PoCs 5
★ 12
Last push 2026-09-21 (2 weeks, 4 days ago)
Fetching description from NVD…
Show 5 repositories
AshleyT3/docker-socket-risk-demos
Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"
★ 0 · 2026-03-31
dfs333/trivysupplychainanalysis
Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM proba…
★ 0 · 2026-07-16
PoCs 12
★ 59
Last push 2026-09-21 (2 weeks, 5 days ago)
Fetching description from NVD…
Show 8 of 12 repositories
gyaansastra/CVE-2023-21716
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF …
★ 59 · 2026-09-21
PoCs 15
★ 624
Last push 2026-09-20 (2 weeks, 5 days ago)
Fetching description from NVD…
Show 8 of 15 repositories
Phlegmelm/CRACK12
rooting an ATOZEE P12 on Android 14 using CVE-2022-38694 — because fastboot oem unlock said no, so we found another way.
★ 5 · 2026-05-14
mutur4/UnisocBootROMs
This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694
★ 5 · 2026-08-11
JoshAtticus/ztewaste
Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.
★ 3 · 2026-06-03
PoCs 24
★ 32
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 24 repositories
lukehebe/CVE-2023-27163-POC
CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerab…
★ 2 · 2025-04-18
PoCs 6
★ 60
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 6 repositories
PoCs 10
★ 9
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
ishankaru/CVE-2026-23111-nftables-lab
Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection, mitigation, m…
★ 2 · 2026-06-11
PoCs 41
★ 142
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 8 of 41 repositories
NiteeshPujari/CVE-2025-32433-PoC
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
★ 7 · 2025-08-14
PoCs 24
★ 353
Last push 2026-09-18 (3 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 24 repositories
MrTiz/CVE-2020-0688
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
★ 22 · 2021-06-06
PoCs 6
★ 4
Last push 2026-09-18 (3 weeks, 1 day ago)
Fetching description from NVD…
Show 6 repositories
bytejmp/MS09-050
MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow exploit with built-in scanner, arch auto-detection, and standalone reverse shell payloads for x86/x64. …
★ 0 · 2026-09-18
PoCs 88
★ 1025
Last push 2026-09-17 (3 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 88 repositories
0x4ndy/clif
clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and …
★ 100 · 2022-12-22
PoCs 5
★ 125
Last push 2026-09-17 (3 weeks, 2 days ago)
Fetching description from NVD…
Show 5 repositories
uLl0a/MSRMapper
MSRMapper is a manual kernel driver mapper for Windows x64 that abuses CVE-2025-8061 in the vulnerable Lenovo driver LnvMSRIO.sys to perform a BYOVD (Bring You…
★ 2 · 2026-09-17
PoCs 14
★ 26
Last push 2026-09-17 (3 weeks, 2 days ago)
Fetching description from NVD…
Show 8 of 14 repositories
Sachinart/CVE-2025-32432
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCM…
★ 26 · 2025-04-27
cd-ratel/CVE-2025-32432
Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning
★ 2 · 2026-05-15
PoCs 7
★ 9
Last push 2026-09-17 (3 weeks, 2 days ago)
Fetching description from NVD…
Show 7 repositories
mt-code/CVE-2019-11447
Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.
★ 0 · 2020-10-20
PoCs 24
★ 44
Last push 2026-09-16 (3 weeks, 3 days ago)
Fetching description from NVD…
Show 8 of 24 repositories
PoCs 14
★ 29
Last push 2026-09-16 (3 weeks, 3 days ago)
Fetching description from NVD…
Show 8 of 14 repositories
obrige/http2-bomb
CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console
★ 4 · 2026-06-05
naheeju/POC-CVE-2026-49975
Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2
★ 3 · 2026-09-16
renzi25031469/CVE-2026-49975-HTTP-2-Bomb
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust se…
★ 2 · 2026-06-08
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.