Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
354PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11114 results

CVE-2026-19553
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/cve-2026-19553-wrap-bio

CPython - High - wrap_bio hostname skip

★ 0 · 2026-10-07
CVE-2026-19445
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/cve-2026-19445-sni-uaf

CPython - Critical - SNI SSLContext UAF

★ 0 · 2026-10-07
CVE-2026-45140
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-45140

CVE-2026-45140 - chamilo - Critical 9.8 - Unauthenticated POST /plugin/CStudio/editor/import-project... - Remote Code Execution

★ 0 · 2026-10-07
CVE-2026-79752
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-79752

CVE-2026-79752 - CakePHP - Critical 9.2 - Unauthenticated GET /?type= - SQL Injection

★ 0 · 2026-10-07
CVE-2026-77635
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-77635

CVE-2026-77635 - CakePHP - Critical 9.2 - Unauthenticated GET /?path= - SQL Injection

★ 0 · 2026-10-07
CVE-2026-18937
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-18937

CVE-2026-18937 - Broken Link Checker - Critical 9.0 - Unauthenticated GET /?page_id=4&shortcode_tags[blcpoc]=po... - Remote Code Execution

★ 0 · 2026-10-07
CVE-2026-81294
FRESH PoC
PoCs 1 ★ 3 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-81294

CVE-2026-81294 - WordPress - Critical 9.8 - Unauthenticated Privilege Escalation

★ 3 · 2026-10-07
CVE-2026-86350
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-444 Published 2026-09-23 PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 9 hours ago)

Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Show 1 repositories
abraxas/CVE-2026-86350

CVE-2026-86350 - Apache Tomcat - Critical 9.1 - Unauthenticated GET /header.jsp - HTTP/2 Request Header Mix-up (Request Smuggling)

★ 1 · 2026-10-07
CVE-2026-75816
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-75816

CVE-2026-75816 - Frontend Admin by DynamiApps for Wordpress - Critical 9.8 - Unauthenticated POST /wp-admin/admin-ajax.php - Account Takeover

★ 0 · 2026-10-07
CVE-2026-19952
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2026-19952

CVE-2026-19952 - DynamiApps - High 7.5 - Unauthenticated POST /wp-admin/admin-ajax.php - Arbitrary File Deletion

★ 0 · 2026-10-07
CVE-2026-103956
FRESH PoC
PoCs 1 ★ 7 Last push 2026-10-07 (3 days, 10 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/cve-2026-103956-loom-unauth

CVE-2026-103956 - Loom for AWS - Critical - Auth bypass - unauthenticated super-admin when no IdP is configured

★ 7 · 2026-10-07
CVE-2026-105221
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 10 hours ago)

Fetching description from NVD…

Show 1 repositories
abraxas/cve-2026-105221-gist-tls

CVE-2026-105221 - gist RubyGem - High - MITM - GitHub OAuth token theft

★ 0 · 2026-10-07
CVE-2026-74727
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 14 hours ago)

Fetching description from NVD…

Show 1 repositories
Kosifuchs/ovpn-kernel-backport

Upstream OpenVPN kernel fix for CVE-2026-74727, tested on Ubuntu kernel 7.0.0-38.38. Includes build instructions and functional test results.

★ 0 · 2026-10-06
CVE-2026-103648
FRESH PoC
PoCs 1 ★ 2 Last push 2026-10-06 (3 days, 14 hours ago)

Fetching description from NVD…

Show 1 repositories
EterNullSec/CVE-2026-103648

CVE-2026-103648 | Path Traversal in image-downloader 4.3.0 | CVSS 9.1 Critical | CWE-22 | By EterNullSec

★ 2 · 2026-10-06
CVE-2026-57967
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-06 (3 days, 14 hours ago)

Fetching description from NVD…

Show 1 repositories
c0dem4sters/CVE-2026-57967

CVE-2026-57967 PoC — Apache ActiveMQ Artemis unauthenticated session hijacking via SESSION_REATTACH (2.50.0–2.56.0)

★ 1 · 2026-10-06
CVE-2011-4825
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 17 hours ago)

Fetching description from NVD…

Show 1 repositories
XavLimSG/Zenphoto-1.4.1.4-CVE-2011-4825-RCE

Python 3 reverse-shell exploit for Zenphoto <= 1.4.1.4 / CVE-2011-4825 (EDB-18083)

★ 0 · 2026-10-06
CVE-2026-3888
FRESH PoCMULTI PoC
PoCs 8 ★ 19 Last push 2026-10-06 (3 days, 18 hours ago)

Fetching description from NVD…

Show 8 repositories
noambouillet/CVE-2026-3888

Linux LPE via snap-confine + systemd-tmpfiles, explained in depth

★ 5 · 2026-04-02
netw0rk7/CVE-2026-3888-PoC
★ 3 · 2026-03-23
fevar54/CVE-2026-3888-POC-all-from-the-Qualys-platform.

PoC de CVE-2026-3888: condicion de carrera en snapd para escalada a root.

★ 2 · 2026-03-18
AlanNewberry/CVE-2026-3888-snap-confine-privilege-escalation

Exploit para CVE-2026-3888: race condition en snap-confine con hijack del loader para escalar a root en Linux.

★ 1 · 2026-10-06
Many-Hat-Group/Ubuntu-CVE-2026-3888-patcher

This is a script designed for deployment on ubuntu instances patching the CVE-2026-3888 exploit

★ 0 · 2026-03-19
DanielTangnes/CVE-2026-3888
★ 0 · 2026-05-19
hewhomusntbenamed/CVE-2026-3888-fixed

CVE-2026-3888 — snap-confine / systemd-tmpfiles SUID LPE (fixed race_pid.txt issue)

★ 0 · 2026-05-12
CVE-2026-59265
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-59265

CVE-2026-59265

★ 0 · 2026-10-06
CVE-2026-63277
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-63277

CVE-2026-63277,

★ 0 · 2026-10-06
CVE-2026-43805
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 1 repositories
WTCYJ/CVE-2026-43805-analysis

One-day analysis + sanitizer PoC of CVE-2026-43805 (IOKit IODMACommand DriverKit RPC race, CWE-362)

★ 0 · 2026-10-06
CVE-2026-67401
FRESH PoCMULTI PoC
PoCs 5 ★ 5 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 5 repositories
imbas007/CVE-2026-67401

PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…

★ 5 · 2026-09-17
axedos/CVE-2026-67401

poc in python for CVE-2026-67401

★ 3 · 2026-09-09
HORKimhab/CVE-2026-67401

CVE-2026-67401 - Draft or TODO

★ 0 · 2026-09-09
jithinkrishnanrs/CVE-2026-67401-cPanel-EmailTrack-SQLi

CVE-2026-67401 cPanel & WHM EmailTrack SQL Injection — IOC scanner, compromise detection, patch verification, incident response and remediation toolkit.

★ 0 · 2026-09-13
hitechcloud-vietnam/CVE-2026-67401

PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…

★ 0 · 2026-10-06
CVE-2026-41940
FRESH PoCHOTMULTI PoC
PoCs 76 ★ 509 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 76 repositories
ynsmroztas/cPanelSniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

★ 509 · 2026-05-01
assetnote/cpanel2shell-scanner

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

★ 92 · 2026-05-18
XsanFlip/poc-cpanel-cve-2026-41940
★ 64 · 2026-05-01
adriyansyah-mf/cve-2026-41940-poc
★ 28 · 2026-04-30
ZeroDayEvil/CVE-2026-41940-PoC
★ 28 · 2026-09-28
Sachinart/CVE-2026-41940-cpanel-0day

CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani

★ 25 · 2026-04-29
ilmndwntr/CVE-2026-41940-MASS-EXPLOIT

CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT

★ 13 · 2026-04-30
rfxn/cpanel-sessionscribe

Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…

★ 13 · 2026-05-21
CVE-2024-21413
FRESH PoCHOTMULTI PoC
PoCs 42 ★ 777 Last push 2026-10-06 (3 days, 20 hours ago)

Fetching description from NVD…

Show 8 of 42 repositories
xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

★ 777 · 2024-02-19
CMNatic/CVE-2024-21413

CVE-2024-21413 PoC for THM Lab

★ 289 · 2024-03-13
duy-31/CVE-2024-21413

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

★ 156 · 2024-02-17
ThemeHackers/CVE-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

★ 25 · 2025-06-05
r00tb1t/CVE-2024-21413-POC

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC

★ 17 · 2024-02-16
mmathivanan17/CVE-2024-21413

Outlook exploitation

★ 11 · 2025-11-30
ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. Monik…

★ 4 · 2024-02-24
CVE-2026-97286
FRESH PoC
CVSS 6.5 MEDIUM CWE-79 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 21 hours ago)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11.

Show 1 repositories
Rully2212/CVE-2026-97286

Technical advisory and proof of concept for CVE-2026-97286 in the WordPress Strong Testimonials plugin

★ 0 · 2026-10-06
CVE-2025-6867
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-06 (3 days, 22 hours ago)

Fetching description from NVD…

Show 1 repositories
richard1026/CVE-2025-6867-reproduction

Set up an environment to reproduce CVE-2025-6867.

★ 0 · 2026-10-06
< Prev Page 11 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.