Fetching description from NVD…
Show 1 repositories
SuiteCRM <= 7.15.1, <= 8.10.1 - Authenticated SSRF
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11114 results
Fetching description from NVD…
SuiteCRM <= 7.15.1, <= 8.10.1 - Authenticated SSRF
Fetching description from NVD…
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation
braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.
Temporary fork of braces with a minimal security patch for CVE-2026-93687, created only to validate dependency override behavior and Fortify/FoD detection befo…
Ubuntu's node-braces plus the CVE-2026-93687 nesting-depth fix, for ppa:pillarsdotnet/ppa
Fetching description from NVD…
🚨 CVE-2023-45866 - BlueDucky Implementation (Using DuckyScript) 🔓 Unauthenticated Peering Leading to Code Execution (Using HID Keyboard)
Exploit basado en vulnerabilidades criticas Bluetooth (CVE-2023-45866, CVE-2024-21306)
CVE-2023-45866 - BluetoothDucky implementation (Using DuckyScript)
Exploits Tested in Mi A2 Lite and Realme 2 pro
BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The attacker's d…
Rust implementation of Marc Newlin's keystroke injection proof of concept (CVE-2023-45866).
EDSEC_BKIF is a keystroke injection tool for Android, Linux, and iOS. With the help of CVE-2023-45866, it grants users unprecedented control over targeted syst…
Fetching description from NVD…
Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…
Fetching description from NVD…
Hands-on cybersecurity and CTF labs covering tabnabbing, login security, web reconnaissance, admin access, service discovery, Nmap, Netdiscover, CVE-2020-23546…
Fetching description from NVD…
FastGPT getTools and runTool SSRF Vulnerability Reproduction
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Educational lab and clean-room reproduction demonstrating the OS command injection pattern in CVE-2026-105134. For defensive research only.
Fetching description from NVD…
r30xlqo6从一个辅助 API 看资源边界:CVE-2026-71486(vLLM)w680rjb2afux
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Runtime exploit monitor for Apple document/image pipelines (iOS/macOS) — EXPMON concept: Frida agent + behavioral rules. First target: the CVE-2026-86950 glyph…
A python tool to detect PDF files exploiting CVE-2026-86950
Out-of-bounds Write (CWE-787)
CVE-2026-86950
Fetching description from NVD…
CVE-2026-46333
CHARON — pre-built PoC for CVE-2026-46333 (Linux ptrace mm==NULL fd theft)
Research on `pidfd_getfd(2)`-based file descriptor leakage from privileged SUID processes. Demonstrates race-condition FD capture against OpenSSH `ssh-keysign`…
Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.
Fetching description from NVD…
A C‑based proof‑of‑concept exploit for CVE‑2025‑54769, automating the creation and upload of a malicious Perl CGI script to LPAR2RRD’s upgrade endpoint, levera…
Fetching description from NVD…
I found an integer overflow that defeats OCaml's fix for CVE-2026-28364: heap memory disclosure and SIGBUS crashes via Marshal deserialization. PoCs, advisory,…
Fetching description from NVD…
CVE-2026-73570
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)
Detection-first, evidence-preserving incident-response toolkit for Zimbra CVE-2026-73570. Includes read-only host checks, IOC feeds, triage, persistence, conta…
CVE-2026-73570
CVE-2026-73570 PoC
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
Fetching description from NVD…
Quick tool for utilizing CVE-2024-31317 on Android
CVE-2024-31317
A command-line utility to exploit Android Zygote injection (CVE-2024-31317)
Detailed discussion of Zygote vulnerability CVE-2024-31317
CVE-2024-31317 Debuggable App Exploit
CVE-2024-31317 Android Zygote命令注入漏洞研究与部署工具 | Android 9-13 漏洞利用框架
Remove Android profile owners/family link with CVE-2024-31317
Fetching description from NVD…
Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts, and attacke…
Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)
Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath, OpenSearch, G…
Claude Code skill to scan machines for Mini Shai-Hulud (CVE-2026-45321) supply chain worm IOCs
IOC checker for the TanStack/Mini Shai-Hulud npm supply chain attack (CVE-2026-45321)
Detects CVE-2026-45321 (TanStack supply chain compromise) and Mini Shai-Hulud worm artifacts. Scans node_modules, lockfiles, persistence hooks (Claude Code, VS…
Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx
🛡️ One-command scanner for CVE-2026-45321 — TanStack npm supply-chain attack
Fetching description from NVD…
ModemManager denial-of-service vulnerability caused by an assertion failure when processing a specially crafted Cell Broadcast Message (CBM).
Fetching description from NVD…
Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in Serverless Fram…
Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends against mar…
Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server s…
Fetching description from NVD…
A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.
Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usa…
Fetching description from NVD…
Gotenberg 8.30.1 unauthenticated RCE exploit
Gotenberg <= 8.30.1 unauthenticated RCE
A Working PoC For CVE-2026-40281
Fetching description from NVD…
This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive s…
Exploit created using Python
Path Traversal vulnerability
Exploit for CVE-2024-46987
CVE-2024-46987 - Camaleon CMS LFI Exploit
This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).
PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.