Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
353PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11114 results

CVE-2026-69137
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
EntroVyx/CVE-2026-69137

SuiteCRM <= 7.15.1, <= 8.10.1 - Authenticated SSRF

★ 0 · 2026-10-05
CVE-2026-33534
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 1 repositories
EntroVyx/CVE-2026-33534

EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation

★ 0 · 2026-10-05
CVE-2026-93687
HIGHFRESH PoC
CVSS 8.7 HIGH CWE-674 Published 2026-09-18 PoCs 2 ★ 0 Last push 2026-10-05 (4 days, 19 hours ago)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

Show 2 repositories
scastillo-jp/braces-fork

Temporary fork of braces with a minimal security patch for CVE-2026-93687, created only to validate dependency override behavior and Fortify/FoD detection befo…

★ 0 · 2026-09-24
pillarsdotnet/node-braces

Ubuntu's node-braces plus the CVE-2026-93687 nesting-depth fix, for ppa:pillarsdotnet/ppa

★ 0 · 2026-10-05
CVE-2023-45866
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 1896 Last push 2026-10-05 (4 days, 19 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
pentestfunctions/BlueDucky

🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)

★ 1896 · 2026-02-11
Danyw24/blueXploit

Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)

★ 16 · 2026-07-23
Eason-zz/BluetoothDucky

CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)

★ 16 · 2024-01-15
AvishekDhakal/CVE-2023-45866_EXPLOITS

Exploits Tested in Mi A2 Lite and Realme 2 pro

★ 3 · 2024-09-02
Sergeb250/BlueDucky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…

★ 2 · 2025-08-26
xG3nesis/RustyInjector

Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).

★ 1 · 2025-01-25
hegaz0y/-BuL

EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…

★ 1 · 2026-05-31
jjjjjjjj987/cve-2023-45866-py
★ 0 · 2024-01-23
CVE-2021-31624
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 20 hours ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-CTF-Labs-Tabnabbing-Web-Recon-Nmap-Netdiscover-CVE-Labs

Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…

★ 0 · 2026-10-05
CVE-2020-23546
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 20 hours ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-CTF-Labs-Tabnabbing-Web-Recon-Nmap-Netdiscover-CVE-Labs

Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…

★ 0 · 2026-10-05
CVE-2026-88629
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-05 (4 days, 22 hours ago)

Fetching description from NVD…

Show 1 repositories
ExploreIO/CVE-2026-88629-fastgpt-mcp-client-ssrf

FastGPT getTools and runTool SSRF Vulnerability Reproduction

★ 1 · 2026-10-05
CVE-2026-41875
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-105319
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
kashishtopi/CVE-2026-105319
★ 0 · 2026-10-05
CVE-2026-105314
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
kashishtopi/CVE-2026-105314
★ 0 · 2026-10-05
CVE-2026-105134
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (4 days, 23 hours ago)

Fetching description from NVD…

Show 1 repositories
RayanAlmulhim/CVE-2026-105134-lab

Educational lab and clean-room reproduction demonstrating the OS command injection pattern in CVE-2026-105134. For defensive research only.

★ 0 · 2026-10-05
CVE-2026-71486
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 1 repositories
tmvictorpeters/jbo4rgl

r30xlqo6从一个辅助 API 看资源边界:CVE-2026-71486(vLLM)w680rjb2afux

★ 0 · 2026-10-05
CVE-2026-86950
HIGHFRESH PoCMULTI PoC
CVSS 8.8 HIGH CWE-787 Published 2026-09-28 PoCs 5 ★ 9 Last push 2026-10-05 (5 days ago)

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Show 5 repositories
msuiche/hotcell

Runtime exploit monitor for Apple document/image pipelines (iOS/macOS) — EXPMON concept: Frida agent + behavioral rules. First target: the CVE-2026-86950 glyph…

★ 9 · 2026-10-02
decalage2/detect_CVE-2026-86950

A python tool to detect PDF files exploiting CVE-2026-86950

★ 4 · 2026-10-02
DeAurity/CVE-2026-86950-POC

Out-of-bounds Write (CWE-787)

★ 2 · 2026-09-29
34zY/CVE-2026-86950
★ 0 · 2026-10-01
0xBlackash/CVE-2026-86950

CVE-2026-86950

★ 0 · 2026-10-05
CVE-2026-46333
FRESH PoCMULTI PoC
PoCs 5 ★ 41 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 5 repositories
0xBlackash/CVE-2026-46333

CVE-2026-46333

★ 41 · 2026-05-17
KaraZajac/CHARON

CHARON — pre-built PoC for CVE-2026-46333 (Linux ptrace mm==NULL fd theft)

★ 8 · 2026-05-17
studiogangster/CVE-2026-46333

Research on `pidfd_getfd(2)`-based file descriptor leakage from privileged SUID processes. Demonstrates race-condition FD capture against OpenSSH `ssh-keysign`…

★ 6 · 2026-05-17
st4rburn/public-passwd

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

★ 4 · 2026-05-17
dr4mohamed/CVE-2026-46333
★ 0 · 2026-10-05
CVE-2025-54769
FRESH PoC
PoCs 2 ★ 2 Last push 2026-10-05 (5 days ago)

Fetching description from NVD…

Show 2 repositories
byteReaper77/CVE-2025-54769

A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, levera…

★ 2 · 2025-07-30
tunahantekeoglu/CVE-2025-54769
★ 0 · 2026-10-05
CVE-2026-28364
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
Akshay-M-Singh/ocaml-marshal-vulnerability

I found an integer overflow that defeats OCaml's fix for CVE-2026-28364: heap memory disclosure and SIGBUS crashes via Marshal deserialization. PoCs, advisory,…

★ 0 · 2026-10-05
CVE-2026-73570
FRESH PoCMULTI PoC
PoCs 9 ★ 4 Last push 2026-10-05 (5 days, 3 hours ago)

Fetching description from NVD…

Show 8 of 9 repositories
HORKimhab/CVE-2026-73570

CVE-2026-73570

★ 4 · 2026-08-25
gabrielunknown/CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

★ 4 · 2026-09-14
jishino567/CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

★ 2 · 2026-08-25
dahnutz/zimbra-cve-2026-73570-ir

Detection-first, evidence-preserving incident-response toolkit for Zimbra CVE-2026-73570. Includes read-only host checks, IOC feeds, triage, persistence, conta…

★ 2 · 2026-10-05
0xBlackash/CVE-2026-73570

CVE-2026-73570

★ 2 · 2026-09-30
BiuTrap/CVE-2026-73570

CVE-2026-73570 PoC

★ 0 · 2026-09-02
INFOKOM-KI/Zimbra-CVE-2026-73570-Rules

Wazuh Rules for Detection Zimbra (CVE-2026-73570).

★ 0 · 2026-08-28
juanpoch/CVE-2026-73570

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

★ 0 · 2026-09-13
CVE-2024-31317
FRESH PoCMULTI PoC
PoCs 14 ★ 92 Last push 2026-10-05 (5 days, 3 hours ago)

Fetching description from NVD…

Show 8 of 14 repositories
wqry085/PoC-Deployer-System

Quick tool for utilizing CVE-2024-31317 on Android

★ 92 · 2026-02-16
fuhei/CVE-2024-31317

CVE-2024-31317

★ 68 · 2024-12-05
Anonymous941/zygote-injection-toolkit

A command-line utility to exploit Android Zygote injection (CVE-2024-31317)

★ 63 · 2025-12-17
agg23/cve-2024-31317

Detailed discussion of Zygote vulnerability CVE-2024-31317

★ 30 · 2025-08-05
CleoV2/Debuggable-App-Exploit

CVE-2024-31317 Debuggable App Exploit

★ 12 · 2026-03-01
fcy10012/CVE-2024-31317-Deployer

CVE-2024-31317 Android Zygote命令注入漏洞研究与部署工具 | Android 9-13 漏洞利用框架

★ 6 · 2025-12-21
rifting/Zygotroller

Remove Android profile owners/family link with CVE-2024-31317

★ 5 · 2025-08-10
CVE-2026-45321
FRESH PoCMULTI PoC
PoCs 12 ★ 2 Last push 2026-10-05 (5 days, 3 hours ago)

Fetching description from NVD…

Show 8 of 12 repositories
Intrudify/mini-shai-hulud-scanner

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacke…

★ 2 · 2026-05-13
fabriziosalmi/tanstack-compromise-checker

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

★ 2 · 2026-10-05
qi-scape/scan-shai-hulud

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath, OpenSearch, G…

★ 1 · 2026-05-12
shayr1/shai-hulud-scan

Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs

★ 1 · 2026-05-13
nkopylov/tanscript-exploit-check

IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)

★ 1 · 2026-05-26
ry-allan/tanstack-compromise-checker

Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks (Claude Code, VS…

★ 0 · 2026-05-24
Yomisana/are-you-get-tanstack-attack

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

★ 0 · 2026-05-13
Caixa-git/tanstack-shield

🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack

★ 0 · 2026-05-12
CVE-2026-95622
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 4 hours ago)

Fetching description from NVD…

Show 1 repositories
0xSemizzz/CVE-2026-95622

ModemManager denial-of-service vulnerability caused by an assertion failure when processing a specially crafted Cell Broadcast Message (CBM).

★ 0 · 2026-10-05
CVE-2025-69256
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-05 (5 days, 5 hours ago)

Fetching description from NVD…

Show 3 repositories
SimoesCTT/CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in Serverless Fram…

★ 0 · 2026-01-28
studiomeyer-io/mcp-server-attestation

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends against mar…

★ 0 · 2026-10-05
studiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server s…

★ 0 · 2026-10-04
CVE-2026-100671
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 9 hours ago)

Fetching description from NVD…

Show 1 repositories
canhieu/cve-2026-100671-poc
★ 0 · 2026-10-05
CVE-2026-86881
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-295 Published 2026-09-14 PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 10 hours ago)

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.

Show 1 repositories
0xcrypto/CVE-2026-86881

Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usa…

★ 0 · 2026-10-05
CVE-2026-40281
FRESH PoC
PoCs 3 ★ 3 Last push 2026-10-05 (5 days, 10 hours ago)

Fetching description from NVD…

Show 3 repositories
MRdark-ops/CVE-2026-40281-exploit

Gotenberg 8.30.1 unauthenticated RCE exploit

★ 3 · 2026-10-04
0xgh057r3c0n/CVE-2026-40281

Gotenberg <= 8.30.1 unauthenticated RCE

★ 0 · 2026-10-01
rabakuku/CVE-2026-40281

A Working PoC For CVE-2026-40281

★ 0 · 2026-10-05
CVE-2024-46987
FRESH PoCMULTI PoC
PoCs 10 ★ 27 Last push 2026-10-04 (5 days, 18 hours ago)

Fetching description from NVD…

Show 8 of 10 repositories
Goultarde/CVE-2024-46987

This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive s…

★ 27 · 2026-05-10
advaitpathak21/CVE-2024-46987

Exploit created using Python

★ 1 · 2026-02-06
L1337Xi/CVE-2024-46987

Path Traversal vulnerability

★ 0 · 2026-02-03
Ik0nw/CVE-2024-46987
★ 0 · 2026-02-04
sparrowhawk1113/Exploit-for-CVE-2024-46987

Exploit for CVE-2024-46987

★ 0 · 2026-02-05
Rival420/CVE-2024-46987

CVE-2024-46987 - Camaleon CMS LFI Exploit

★ 0 · 2026-02-05
ramzerk/CVE-2024-46987

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

★ 0 · 2026-02-09
BLUEBERRYP1LL/CVE-2024-46987

PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)

★ 0 · 2026-02-22
< Prev Page 13 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.