Fetching description from NVD…
Show 1 repositories
CPython - High - wrap_bio hostname skip
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11114 results
Fetching description from NVD…
CPython - High - wrap_bio hostname skip
Fetching description from NVD…
CPython - Critical - SNI SSLContext UAF
Fetching description from NVD…
CVE-2026-45140 - chamilo - Critical 9.8 - Unauthenticated POST /plugin/CStudio/editor/import-project... - Remote Code Execution
Fetching description from NVD…
CVE-2026-79752 - CakePHP - Critical 9.2 - Unauthenticated GET /?type= - SQL Injection
Fetching description from NVD…
CVE-2026-77635 - CakePHP - Critical 9.2 - Unauthenticated GET /?path= - SQL Injection
Fetching description from NVD…
CVE-2026-18937 - Broken Link Checker - Critical 9.0 - Unauthenticated GET /?page_id=4&shortcode_tags[blcpoc]=po... - Remote Code Execution
Fetching description from NVD…
CVE-2026-81294 - WordPress - Critical 9.8 - Unauthenticated Privilege Escalation
Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
CVE-2026-86350 - Apache Tomcat - Critical 9.1 - Unauthenticated GET /header.jsp - HTTP/2 Request Header Mix-up (Request Smuggling)
Fetching description from NVD…
CVE-2026-75816 - Frontend Admin by DynamiApps for Wordpress - Critical 9.8 - Unauthenticated POST /wp-admin/admin-ajax.php - Account Takeover
Fetching description from NVD…
CVE-2026-19952 - DynamiApps - High 7.5 - Unauthenticated POST /wp-admin/admin-ajax.php - Arbitrary File Deletion
Fetching description from NVD…
CVE-2026-103956 - Loom for AWS - Critical - Auth bypass - unauthenticated super-admin when no IdP is configured
Fetching description from NVD…
CVE-2026-105221 - gist RubyGem - High - MITM - GitHub OAuth token theft
Fetching description from NVD…
Upstream OpenVPN kernel fix for CVE-2026-74727, tested on Ubuntu kernel 7.0.0-38.38. Includes build instructions and functional test results.
Fetching description from NVD…
CVE-2026-103648 | Path Traversal in image-downloader 4.3.0 | CVSS 9.1 Critical | CWE-22 | By EterNullSec
Fetching description from NVD…
CVE-2026-57967 PoC — Apache ActiveMQ Artemis unauthenticated session hijacking via SESSION_REATTACH (2.50.0–2.56.0)
Fetching description from NVD…
Python 3 reverse-shell exploit for Zenphoto <= 1.4.1.4 / CVE-2011-4825 (EDB-18083)
Fetching description from NVD…
Linux LPE via snap-confine + systemd-tmpfiles, explained in depth
PoC de CVE-2026-3888: condicion de carrera en snapd para escalada a root.
Exploit para CVE-2026-3888: race condition en snap-confine con hijack del loader para escalar a root en Linux.
This is a script designed for deployment on ubuntu instances patching the CVE-2026-3888 exploit
CVE-2026-3888 — snap-confine / systemd-tmpfiles SUID LPE (fixed race_pid.txt issue)
Fetching description from NVD…
CVE-2026-59265
Fetching description from NVD…
CVE-2026-63277,
Fetching description from NVD…
One-day analysis + sanitizer PoC of CVE-2026-43805 (IOKit IODMACommand DriverKit RPC race, CWE-362)
Fetching description from NVD…
PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…
poc in python for CVE-2026-67401
CVE-2026-67401 - Draft or TODO
CVE-2026-67401 cPanel & WHM EmailTrack SQL Injection — IOC scanner, compromise detection, patch verification, incident response and remediation toolkit.
PoC for CVE-2026-67401 — cPanel/WHM EmailTrack SQL injection leading to arbitrary file write and root RCE. Includes a self-contained vulnerable lab, SQLi detec…
Fetching description from NVD…
CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)
CVE-2026-41940 latest cPanel & WHM 0day - 70 million websites are possible to expose by Chirag Artani
CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT
Detection, mitigation, and reverse-engineering tooling for CVE-2026-41940 (SessionScribe): the cPanel/WHM unauthenticated session-forgery vulnerability disclos…
Fetching description from NVD…
Microsoft-Outlook-Remote-Code-Execution-Vulnerability
CVE-2024-21413 PoC for THM Lab
Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC
CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC
Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC
Outlook exploitation
Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. Monik…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11.
Technical advisory and proof of concept for CVE-2026-97286 in the WordPress Strong Testimonials plugin
Fetching description from NVD…
Set up an environment to reproduce CVE-2025-6867.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.