Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
357PoC updated in 7 days
filters
11117 results
CVSS 9.3 CRITICAL
CWE-444
Published 2026-09-27
PoCs 1
★ 1
Last push 2026-10-02 (1 week ago)
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
les-k/wp-secure-mcp
A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by never havi…
★ 0 · 2026-10-02
CVSS 9.8 CRITICAL
CWE-862
Published 2026-10-02
PoCs 1
★ 0
Last push 2026-10-02 (1 week ago)
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 1
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 10
★ 75
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
exfil0/CVE-2024-55591-POC
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in cert…
★ 12 · 2025-05-26
virus-or-not/CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-…
★ 8 · 2025-01-29
uLl0a/cve-2024-55591-poc
Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability assessment, and und…
★ 1 · 2026-09-18
PoCs 1
★ 0
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 1
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 1
Last push 2026-10-02 (1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 3
★ 3
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 3 repositories
PoCs 6
★ 5
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 6 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
riddhimaan-sth404/CVE-2026-57973
CVE-2026-57973 is a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Microsoft Windows Subsystem for Linux (WSL2) that allows an autho…
★ 0 · 2026-10-02
PoCs 2
★ 1
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 2 repositories
murrez/CVE-2026-14378
PoC for CVE-2026-14378: DevKit Pro ≤2.3.0 unauthenticated admin takeover via original_user_id cookie + revert_switch nonce. check/admin + mass scan.
★ 1 · 2026-10-02
PoCs 1
★ 0
Last push 2026-10-02 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 5
★ 9
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 5 repositories
LucasKatashi/paint2die
Simplest and most reliable RichFaces Paint2DResource CVE-2018-12533 RF-14310 exploit PoC
★ 1 · 2025-11-25
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
pervinzahidli/CVE-2026-104110
Unauthenticated disclosure of internal folder path, client email, and upload policy for FileRise Pro client portals via /api/pro/portals/get.php
★ 0 · 2026-10-01
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 3
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 1 day ago)
Fetching description from NVD…
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.