Fetching description from NVD…
Show 1 repositories
A python3 PoC for CVE-2026-105030 Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
A python3 PoC for CVE-2026-105030 Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API
Fetching description from NVD…
Linux Kernel Exploits -> CVE-2008-0600 + CVE-2008-0900 + CVE-2008-4210
An end-to-end infrastructure penetration testing lab showcasing automated scanning (Nikto), remote code execution (CVE-2012-1823), and manual kernel privilege …
Fetching description from NVD…
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 pro…
The PoC for CVE-2025-70795 / CVE-2026-0828 and updated driver
Kernel Process Termination Tool ( CVE-2026-0828 exploit)
BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).
Ring0-level process killer leveraging CVE-2026-0828 (BYOVD). Designed to demonstrate kernel-level process termination via a vulnerable signed driver, highlight…
CVE-2026-0828
Fetching description from NVD…
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 pro…
ThrottleStop.sys Arbitrary Physical Memory R/W
CVE-2025-7771: Arbitrary physical memory and I/O port read/write via ThrottleStop driver
Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel security research
Escalating privilege in the system from unsigned driver using throttlestop vulnerability
Arbitrary Function Call Exploit using the ThrottleStop driver
CVE-2025-7771 ThrottleStop.sys privilege escalation exploit - unrestricted IOCTL access to physical memory via MmMapIoSpace
A simple PoC demonstrating the vulnerability in the ThrottleStop.sys driver, showcasing arbitrary physical memory read and write capabilities, as well as virtu…
Fetching description from NVD…
A PoC for CVE-2025-21065 that allows any self-attacker to execute commands with Retail Mode privileges (UID 1000/GID 1000, u:r:system_app:s0)
Fetching description from NVD…
FortiSandbox RCE Scanner — CVE-2026-39808
PoC for Unauthenticated RCE in FortiSandbox via CVE-2026-39808
CVE-2026-39808
An unauthenticated OS command injection vulnerability
CVE-2026-39808 - Fortinet Sandbox - Draft
Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint
Fetching description from NVD…
CVE-2026-4480
smb spooler to RCE
Exploit para CVE-2026-4480: inyeccion de comandos en la variable %J del print command de Samba para RCE sin autenticacion via spoolss.
Exploit CVE-2026-4480
This is an exploit poc for CVE-2026-4480
🔴 HackTheBox Abducted (Medium) — CVE-2026-4480 (Samba %J) → rclone reveal → SMB-Symlink → systemd Drop-in → Root
Fetching description from NVD…
Proof-of-concept scanner and exploit helper for CVE-2026-14378: unauthenticated administrator session takeover in the WordPress plugin DevKit Pro (dplugins) th…
Divi Membership (DiviEngine) pre-auth admin takeover — CVE-2026-19660 paypal_param bypass. Python PoC with exploit + cookie export.
Fetching description from NVD…
Hands-on Learn SecByte CTF labs covering Beelzebub preparation, VM and network clues, Base64, CVE-2026-14461, admin panels, authentication, credential leaks, k…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
Fetching description from NVD…
CVE-2026-48842 PoC — Roundcube virtuser_query pre-auth SQLi
Roundcube virtuser_query pre-auth SQLi (CVE-2026-48842). Python PoC — version detect, virtuser plugin, login probe. https://pocbit.org
CVE-2026-48842 Roundcube SQLi Verifier
Fetching description from NVD…
Isolated ASan/UBSan reproduction and patch verification lab for public CVE-2022-0891
Fetching description from NVD…
A PoC of the CVE-2024-56426 vulnerability.
CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F
Fetching description from NVD…
🛡️ Official AI Security Tool module for CVE-2026-41096 (Windows DNSAPI.dll Heap Overflow / DNS-Mayhem Deep Dive Analysis & Audit Module).
windows api bug
Attack surface in the real-world environment of CVE-2026-41096
In‑depth technical analysis of CVE‑2026‑41096, a critical heap overflow in Windows DNSAPI.dll enabling remote code execution via crafted DNS responses. Include…
CVE-2026-41096: Heap Overflow in the Windows DNS Client
Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.
Fetching description from NVD…
Proof of Concept (PoC) for CVE-2026-64638, a reflected XSS in WordPress Core < 7.0.3.
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.
Proof of concept for CVE-2026-92592: Craft CMS authenticated RCE
Fetching description from NVD…
CVE 2021-21315 PoC
rust noob tried write easy exploit code with rust lang
systeminformation
Thesis scenario test (research only): Scenario D: KEV override path - [email protected] CVE-2021-21315
Fetching description from NVD…
Exploit de reverseshell para desserialização em NodeJs (CVE-2017-5941)
Ejecución de exploit de deserialización con CVE-2017-5941
Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941
Thesis scenario test (research only): Scenario C: EPSS-BLOCK path - [email protected] CVE-2017-5941
Fetching description from NVD…
AURORA demo target — deliberately vulnerable lockfiles (CVE-2019-10744, CVE-2018-18074, CVE-2020-26160)
Thesis scenario test (research only): Scenario B: WARN path - [email protected] CVE-2019-10744 (known-vulnerable dependency, low EPSS)
Fetching description from NVD…
A PoC for ZDI-CAN-28834/CVE-2026-83603, which allows local privilege escalation using netdata and fail2ban-client
A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.
Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)
Fetching description from NVD…
Unauthenticated Privilege Escalation Mass Exploit Super Forms <= 6.3.316 CVE-2026-15989
SFADMIN - CVE-2026-15989 Super Forms <= 6.3.316 unauthenticated privilege escalation (mass scanner + exploit)
Fetching description from NVD…
CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction
CVE-2026-102282: adm-zip LPE via SUID/SGID preservation during archive extraction (fixed in 0.6.1)
Fetching description from NVD…
Fetching description from NVD…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.