Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
357PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVE-2026-88773
CRITICAL
CVSS 9.3 CRITICAL CWE-444 Published 2026-09-27 PoCs 1 ★ 1 Last push 2026-10-02 (1 week ago)

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

Show 1 repositories
Scyrix-LLC/CVE-2026-88773

CVE-2026-88773

★ 1 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
les-k/wp-secure-mcp

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by never havi…

★ 0 · 2026-10-02
CVE-2026-94541
CRITICAL
CVSS 9.8 CRITICAL CWE-862 Published 2026-10-02 PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.

Show 1 repositories
anoxhunterdump-ctrl/CVE-2026-94541-WPMobileApp-AuthBypass

Defensive analysis, detection scanner, and rule signatures for CVE-2026-94541 (WPMobile.App <= 11.82).

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
overgrowncarrot1/Instatic-Stored-XSS-CVE-2026-103931

CVE-2026-103931

★ 0 · 2026-10-02
PoCs 1 ★ 1 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
lowlevelsec/AVM-FRITZ-Box-CVE-2024-54767-Exploit

Research & PoC for CVE-2024-54767 and related unauthenticated FRITZ!OS information-disclosure findings across multiple FRITZ!Box models and firmware versions.

★ 1 · 2026-10-02
CVE-2024-55591
MULTI PoC
PoCs 10 ★ 75 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 8 of 10 repositories
exfil0/CVE-2024-55591-POC

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability (CVE-2024-55591) in cert…

★ 12 · 2025-05-26
virus-or-not/CVE-2024-55591

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-…

★ 8 · 2025-01-29
UMChacker/CVE-2024-55591-POC
★ 2 · 2025-05-26
uLl0a/cve-2024-55591-poc

Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability assessment, and und…

★ 1 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
covepseng/cve-2026-102268-poc

Exploitability PoC for CVE-2026-102-268 (PyJWT Asymmetric-PEM detection bypass).

★ 0 · 2026-10-02
PoCs 1 ★ 1 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
KiwKNR/CVE-2026-104826

CVE-2026-104826: path traversal to RCE in DropzoneFileExplorer chunked upload handler

★ 1 · 2026-10-02
PoCs 1 ★ 1 Last push 2026-10-02 (1 week ago)

Fetching description from NVD…

Show 1 repositories
KiwKNR/CVE-2026-103978

CVE-2026-103978: unauthenticated path traversal (arbitrary .json read) in OPNMGR

★ 1 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
MRdark-ops/CVE-2026-55559

Unauthenticated RCE in Yamcs mission control via YAML injection in reconfigureInstance()

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
overgrowncarrot1/PenPot-RCE

Penpot <2.15.0 allows for unathenticated RCE CVE-2026-45805

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
LanBaiCode/CVE-2025-45737

利用CVE-2025-45737漏洞,实现提权

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
techupdate24/capacitor-flaw-cve-2026-103922

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-02
PoCs 3 ★ 3 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 3 repositories
fatkz/CVE-2025-24801

CVE-2025-24801 Exploit

★ 3 · 2025-05-07
r1beirin/Exploit-CVE-2025-24801
★ 1 · 2025-04-21
CVE-2026-44011
MULTI PoC
PoCs 6 ★ 5 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 6 repositories
4xura/CVE-2026-44011-craftcms-auth-rce

The PoC of CVE-2026-44011: Craft CMS RCE with an authenticated user.

★ 5 · 2026-09-27
Cyberuser-hash/CVE-2026-44011-craft-rce-poc

CVE-2026-44011-craft-rce-poc

★ 2 · 2026-09-27
khush-613/CVE-2026-44011-poc
★ 1 · 2026-09-27
TRX-0/CVE-2026-44011-craftcms-rce

Craft CMS CVE-2026-44011 condition FieldLayout RCE PoC

★ 0 · 2026-09-21
DENNISDGR/CVE-2026-44011-poc

Authenticated Craft CMS RCE PoC for CVE-2026-44011

★ 0 · 2026-09-27
0xyngtg/CraftCMS-CVE-2026-44011-PoC-RCE

This is a PoC of the CVE-2026-44011 found by precicom-vincent-tl. For more details check: https://github.com/advisories/GHSA-qrgm-p9w5-rrfw

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
0xBlackash/CVE-2026-63292

CVE-2026-63292

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
riddhimaan-sth404/CVE-2026-57973

CVE-2026-57973 is a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Microsoft Windows Subsystem for Linux (WSL2) that allows an autho…

★ 0 · 2026-10-02
PoCs 2 ★ 1 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 2 repositories
murrez/CVE-2026-14378

PoC for CVE-2026-14378: DevKit Pro ≤2.3.0 unauthenticated admin takeover via original_user_id cookie + revert_switch nonce. check/admin + mass scan.

★ 1 · 2026-10-02
anoxhunterdump-ctrl/CVE-2026-14378-DevKit-Pro-Auth-Bypass

Defensive analysis, patch breakdown, and detection scanner for CVE-2026-14378 (WordPress DevKit Pro Plugin <= 2.3.0).

★ 0 · 2026-10-02
PoCs 1 ★ 0 Last push 2026-10-02 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
anoxhunterdump-ctrl/CVE-2026-103752-Authorizer-Privilege-Escalation

Defensive analysis, patch breakdown, and passive detection scanner for CVE-2026-103752 (WordPress Authorizer Plugin <= 3.15.3).

★ 0 · 2026-10-02
CVE-2018-12533
MULTI PoC
PoCs 5 ★ 9 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 5 repositories
llamaonsecurity/CVE-2018-12533

RF-14310 / CVE-2018-12533 - Payload generator

★ 9 · 2022-07-07
Pastea/CVE-2018-12533
★ 1 · 2021-11-08
LucasKatashi/paint2die

Simplest and most reliable RichFaces Paint2DResource CVE-2018-12533 RF-14310 exploit PoC

★ 1 · 2025-11-25
arslanben/richfaces-paint2d-lab

Deliberately vulnerable CTF lab reproducing CVE-2018-12533 (RichFaces Paint2DResource EL injection) end to end.

★ 1 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
pervinzahidli/CVE-2026-104110

Unauthenticated disclosure of internal folder path, client email, and upload policy for FileRise Pro client portals via /api/pro/portals/get.php

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
pervinzahidli/CVE-2026-103977

Session-scoped TOTP rate limiting permits repeated verification attempts

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
yel1337/CVE-2025-47947

POC for libapache2-mod-security2

★ 0 · 2026-10-01
PoCs 1 ★ 3 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
elvira-alec/fracture

FragAttacks WiFi penetration framework — CVE-2020-24586/87/88

★ 3 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Fetching description from NVD…

Show 1 repositories
< Prev Page 16 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.