Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

8 results

CVE-2026-24046
NEWHIGHFRESH PoC
CVSS 7.1 HIGH CWE-22, CWE-59 Published 2026-01-21 PoCs 1 ★ 0 Last push 2026-10-09 (14 hours, 35 minutes ago) Discovered 2026-10-09 14:08

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Show 1 repositories
Rem1L/cve-2026-24046-poc
★ 0 · 2026-10-09
CVE-2024-36774
NEWHIGHFRESH PoC
CVSS 7.2 HIGH CWE-434 Published 2024-06-06 PoCs 1 ★ 0 Last push 2026-10-09 (15 hours, 35 minutes ago) Discovered 2026-10-09 14:08

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Show 1 repositories
CVE-2026-28775
NEWCRITICALFRESH PoC
CVSS 10.0 CRITICAL CWE-1188 Published 2026-03-04 PoCs 1 ★ 0 Last push 2026-10-09 (16 hours, 11 minutes ago) Discovered 2026-10-09 14:08

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Show 1 repositories
Udyz/CVE-2026-28775

CVE-2026-28775 SNMP RCE

★ 0 · 2026-10-09
CVE-2026-107406
NEWCRITICALFRESH PoC
CVSS 9.5 CRITICAL CWE-119 Published 2026-10-08 PoCs 2 ★ 0 Last push 2026-10-09 (18 hours, 31 minutes ago) Discovered 2026-10-09 14:08

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Show 2 repositories
techupdate24/citrix-netscaler-rce-cve-2026-107406

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-09
ApexBreach/CVE-2026-107406-Poc
★ 0 · 2026-10-09
CVE-2022-21812
NEWHIGHFRESH PoC
CVSS 7.8 HIGH Published 2022-08-18 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 20 minutes ago) Discovered 2026-10-09 14:08

Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Show 1 repositories
CVE-2026-95149
NEWFRESH PoC
PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 52 minutes ago) Discovered 2026-10-09 14:08

Fetching description from NVD…

Show 1 repositories
reputati0n/CVE-2026-95149
★ 0 · 2026-10-09
CVE-2025-41249
NEWHIGHFRESH PoC
CVSS 7.5 HIGH CWE-285 Published 2025-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (21 hours, 42 minutes ago) Discovered 2026-10-09 14:08

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .

Show 1 repositories
edwin/simulating-cve-2025-41249
★ 0 · 2026-10-09
CVE-2026-94597
NEWFRESH PoC
PoCs 1 ★ 0 Last push 2026-10-09 (23 hours, 16 minutes ago) Discovered 2026-10-09 14:08

Fetching description from NVD…

Show 1 repositories
canhieu/CVE-2026-94597-poc

CVE-2026-94597

★ 0 · 2026-10-09

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.