Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
14 contacts in last 24h
11117CVEs tracked
26011PoC repositories
20New in 24h
357PoC updated in 7 days
filters
11117 results
PoCs 3
★ 0
Last push 2026-10-05 (5 days, 6 hours ago)
Fetching description from NVD…
Show 3 repositories
studiomeyer-io/mcp-server-attestation
Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends against mar…
★ 0 · 2026-10-05
studiomeyer-io/mcp-stdio-shellguard
Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security 200k-server s…
★ 0 · 2026-10-04
PoCs 1
★ 0
Last push 2026-10-05 (5 days, 10 hours ago)
Fetching description from NVD…
Show 1 repositories
CVSS 9.1 CRITICAL
CWE-295
Published 2026-09-14
PoCs 1
★ 0
Last push 2026-10-05 (5 days, 11 hours ago)
A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.
Show 1 repositories
0xcrypto/CVE-2026-86881
Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usa…
★ 0 · 2026-10-05
PoCs 3
★ 3
Last push 2026-10-05 (5 days, 11 hours ago)
Fetching description from NVD…
Show 3 repositories
PoCs 10
★ 27
Last push 2026-10-04 (5 days, 18 hours ago)
Fetching description from NVD…
Show 8 of 10 repositories
Goultarde/CVE-2024-46987
This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive s…
★ 27 · 2026-05-10
ramzerk/CVE-2024-46987
This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).
★ 0 · 2026-02-09
PoCs 7
★ 559
Last push 2026-10-04 (5 days, 19 hours ago)
Fetching description from NVD…
Show 7 repositories
reswitched/rcm-modchips
Collection of "modchip" designs for launching payloads via the Tegra RCM bug (CVE-2018-6242)
★ 21 · 2018-05-22
nikameru/nxboot
Payload injection tool for Nintendo Switch consoles vulnerable to CVE-2018-6242 ("Fusée Gelée")
★ 2 · 2026-10-04
Resi-le/NXLoader
An app that enables payload injection into a Switch console from an Android device by exploiting the CVE-2018-6242 vulnerability
★ 1 · 2025-12-21
oliviaholly/fusee-gelee
An implementation of the Fusee Gelee exploit (CVE-2018-6242) for the Nintendo Switch, along with a custom payload.
★ 0 · 2026-03-30
PoCs 2
★ 7
Last push 2026-10-04 (5 days, 19 hours ago)
Fetching description from NVD…
Show 2 repositories
PoCs 10
★ 22
Last push 2026-10-04 (5 days, 19 hours ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 1
★ 0
Last push 2026-10-04 (5 days, 20 hours ago)
Fetching description from NVD…
Show 1 repositories
K52-ai/CVE-2026-83627
CVE-2026-83627 — Hummingbird Performance <= 3.21.0 Unauthenticated RCE. Pure Python exploit. by K52-ai.
★ 0 · 2026-10-04
PoCs 1
★ 0
Last push 2026-10-04 (5 days, 20 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-04 (5 days, 21 hours ago)
Fetching description from NVD…
Show 1 repositories
xiaoqiMikko/jackson-check
jackson-databind + jackson-core 26 条安全公告自查:按坐标逐条求交集给出真正到位的版本(2.18.11/2.21.7/2.22.3/3.1.7/3.2.3,2.21.6 已不够);扫源码降噪告诉你真中几条;含 1 条 GitHub 全局库未收录、Dependabot 不报的(jack…
★ 0 · 2026-10-04
PoCs 1
★ 1
Last push 2026-10-04 (5 days, 23 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 2
Last push 2026-10-04 (6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 2
Last push 2026-10-04 (6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 4
Last push 2026-10-04 (6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-04 (6 days ago)
Fetching description from NVD…
Show 1 repositories
wvllxe/CVE-2026-104991
CVE-2026-104991 — Missing Authorization (BOLA/IDOR) in Phproject REST API read/comment endpoints
★ 0 · 2026-10-04
CVSS 9.1 CRITICAL
CWE-94
Published 2026-10-03
PoCs 1
★ 0
Last push 2026-10-04 (6 days, 3 hours ago)
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.
Show 1 repositories
PoCs 3
★ 2
Last push 2026-10-04 (6 days, 3 hours ago)
Fetching description from NVD…
Show 3 repositories
DeadExpl0it/CVE-2026-19632-POC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
★ 0 · 2026-08-27
PoCs 8
★ 89
Last push 2026-10-04 (6 days, 4 hours ago)
Fetching description from NVD…
Show 8 repositories
GiZcesi/HJregsvr32
Educational PoC for CVE-2025-49144 (regsvr32 LOLBIN) — authorized lab use only
★ 0 · 2026-10-04
PoCs 10
★ 93
Last push 2026-10-04 (6 days, 8 hours ago)
Fetching description from NVD…
Show 8 of 10 repositories
adibirzu/openclaw-security-monitor
Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.
★ 48 · 2026-10-04
siyad01/agentbox
Open-source sandboxed runtime for AI agents — gVisor/Docker isolation, credential vault, immutable audit log. Built after CVE-2026-25253.
★ 1 · 2026-05-11
PoCs 1
★ 0
Last push 2026-10-04 (6 days, 9 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 9
★ 10
Last push 2026-10-03 (6 days, 15 hours ago)
Fetching description from NVD…
Show 8 of 9 repositories
gunzf0x/CVE-2025-60787
PoC for CVE-2025-60787 - Authenticated RCE in motionEye for all versions up to 0.43.1b4 (included)
★ 10 · 2026-03-08
d3vn0mi/CVE-2025-60787-POC
Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config
★ 0 · 2026-03-13
PoCs 7
★ 9
Last push 2026-10-03 (6 days, 15 hours ago)
Fetching description from NVD…
Show 7 repositories
Skynoxk/CVE-2026-27944
Automated exploit script for CVE-2026-27944 (Nginx UI). Downloads/decrypts backups, extracts system secrets, and creates rogue admin accounts for full dashboar…
★ 9 · 2026-03-14
karimelsheikh1/HTB-Snapped-Writeup
HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race condition LPE) to …
★ 1 · 2026-05-07
PoCs 9
★ 14
Last push 2026-10-03 (6 days, 15 hours ago)
Fetching description from NVD…
Show 8 of 9 repositories
0xDaeras/CVE-2024-51482-POC
Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.
★ 7 · 2026-05-09
PoCs 3
★ 4
Last push 2026-10-03 (6 days, 15 hours ago)
Fetching description from NVD…
Show 3 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.