Fetching description from NVD…
Show 1 repositories
CVE-2026-102422 POC
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11114 results
Fetching description from NVD…
CVE-2026-102422 POC
Fetching description from NVD…
Smarty is vulnerable to code injection through template inheritance. Crafted assigned data can inject a forged SmartyNocache marker into regenerated PHP cache …
Fetching description from NVD…
Tracking DiagSpill (CVE-2026-74469), the Linux kernel SCTP sock_diag heap overflow
CVE-2026-74469
CVE-2026-74469 DiagSpill
Fetching description from NVD…
First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).
Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization
CVE-2026-33439
Vulnerable endpoint description for CVE-2026-33439 in OpenAM
CVE-2026-33439 OpenAM pre-auth RCE PoC
Proof of concept for CVE-2026-33439, an unauthenticated RCE in OpenAM via Java deserialization
CVE-2026-33439
Fetching description from NVD…
CVE-2026-59358 - Cloud Foundry UAA - High - Remote - Privilege leftover - user PKCE token as client_credentials Bearer
Fetching description from NVD…
CVE-2022-0185
CVE-2022-0185 POC and Docker and Analysis write up
CVE-2022-0185 exploit rewritten with pipe primitive
CVE-2022-0185 exploit
Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.
Fetching description from NVD…
CVE-2026-19089 WooCommerce Tych Remote Command Execution
Fetching description from NVD…
SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced P…
Fetching description from NVD…
CVE-2026-82226 - Tickera - Critical 9.8 - Unauthenticated POST /cart/ - PHP Object Injection
Fetching description from NVD…
CVE-2026-78159 - stellarwp - Critical 9.8 - Unauthenticated POST /wp-comments-post.php - Remote Code Execution
A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.
CVE-2026-96512 - sudo - High 7.8 - Authenticated LOCAL TZ=UTC+14 sudo -n /usr/bin/id - Local Privilege Escalation via Time-Window Bypass
Fetching description from NVD…
CVE-2026-22599 - Strapi - Critical 9.3 - Authenticated POST /content-type-builder/content-types - Authenticated SQL Injection (Knex raw defaultTo)
Fetching description from NVD…
CVE-2026-52782 - OpenProject - Critical 9.9 - Authenticated PATCH /projects/{identifier}/settings/project_storages/{id} - Authenticated IDOR (Project Storage F…
Fetching description from NVD…
CVE-2026-61628 - nginx-ignition - High 8.1 - Unauthenticated Privilege Escalation (Administrator Account Creation)
Fetching description from NVD…
CVE-2026-13447 - WordPress - inspireui - Critical 9.8 - Unauthenticated POST /wp-json/api/flutter_user/firebase_sms_v2 - Authentication Bypass
Fetching description from NVD…
CVE-2026-84753 - WPFunnels - Critical 9.8 - Unauthenticated POST /?rest_route=/mint-mail/v1/mint-form-... - PHP Object Injection
Fetching description from NVD…
Private HTTP-only reproduction of CVE-2026-75650 StyleSmuggler
Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magen…
StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence ar…
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-ado…
CVE-2026-75650 - Magento Open Source - Critical 10.0 - Unauthenticated POST /graphql - Unauthenticated Remote Code Execution (StyleSmuggler SSTI)
Fetching description from NVD…
CVE-2026-48356 - Magento Open Source - Critical 9.3 - Unauthenticated POST /rest/default/V1/guest-carts/{cartId}/items - Unauthenticated Unrestricted File Uplo…
Fetching description from NVD…
CVE-2026-12793 PoC — JetFormBuilder ≤3.6.2 unauth Register User / admin account creation
CVE-2026-12793 - JetFormBuilder Unauthorized RCE (CRITICAL 9.8)
Fetching description from NVD…
CVE-2026-77991 - joomlaeventmanager.net - Critical - Privileged POST /administrator/index.php - Remote Code Execution
Fetching description from NVD…
CVE-2026-75827 - getgrav - High 8.8 - Unauthenticated GET /poc-form - Arbitrary File Write
Fetching description from NVD…
CVE-2026-15583 - Grafana MCP Server - High 8.6 - Unauthenticated POST /mcp - Unauthenticated Token Exfiltration (X-Grafana-URL Confused Deputy)
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2026-87796 - Multi Uploader for Gravity Forms <= 1.1.9; Unauthorized RCE (CRITICAL 9.8)
Fetching description from NVD…
CVE-2026-62062 - WordPress - Elementor Website Builder - High 8.8 - Unauthenticated POST /?rest_route=/wp/v2/users&x=elementor... - Cross-Site Request Forgery …
Fetching description from NVD…
CVE-2026-81648 - WordPress - CryptoPayment Gateway - Critical 10.0 - Unauthenticated POST /wp-content/plugins/cryptopayment-gateway/vendor/cryptd/ajax.php - Ar…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.