Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
355PoC updated in 7 days
filters
11117 results
CVSS 9.8 CRITICAL
CWE-73, CWE-94
Published 2026-09-20
PoCs 5
★ 2
Last push 2026-10-01 (1 week, 2 days ago)
An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.
Show 5 repositories
murrez/CVE-2026-90817
Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation.
★ 2 · 2026-09-21
CVSS 6.9 MEDIUM
CWE-639
Published 2026-09-29
PoCs 1
★ 1
Last push 2026-10-01 (1 week, 2 days ago)
Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.
Show 1 repositories
aorozco-sys/CVE-2026-90907
CVE-2026-90907 (CVSS 6.9) — Joomla! CMS unauthorized user account creation via com_users profile.save (authorization bypass). Non-destructive checker + authori…
★ 1 · 2026-10-01
PoCs 19
★ 80
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 19 repositories
PoCs 20
★ 37
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 20 repositories
Chocapikk/CVE-2023-28432
Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.
★ 11 · 2026-01-08
CVSS 9.8 CRITICAL
CWE-22
Published 2026-09-22
PoCs 2
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Show 2 repositories
PoCs 3
★ 1
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 3 repositories
CVSS 6.1 MEDIUM
CWE-79
Published 2026-09-25
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on forms whose admin-authored confirmation message places the {page_title} Smart Tag inside an HTML attribute context.
Show 1 repositories
PoCs 84
★ 3551
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 84 repositories
amlweems/xzbot
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
★ 3551 · 2024-04-03
PoCs 58
★ 195
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813
his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…
★ 195 · 2025-03-14
x00byte/PutScanner
A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]
★ 9 · 2025-07-19
PoCs 2
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 2 repositories
murrez/CVE-2026-102425
CVE-2026-102425 PoC (PoCbit) — Joomla Balbooa Forms (com_baforms) <2.4.3.4 unauth RCE via field shortcode injection in post-submission PHP eval(). check + expl…
★ 0 · 2026-09-30
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 1 repositories
Rollingzzzzz/heif-heist-lab
HEIF Heist lab — reproduce the Meta $115K HEIC upload bug (CVE-2025-46087) in Docker: crafted HEIC → heap disclosure → admin secrets leak into your profile pic…
★ 0 · 2026-10-01
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 25
★ 339
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 25 repositories
peterpt/eternal_scanner
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
★ 339 · 2024-07-31
AtithKhawas/autoblue
AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …
★ 5 · 2024-12-30
sethwhy/BlueDoor
Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…
★ 2 · 2024-12-22
PoCs 30
★ 2
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 30 repositories
mk017-hk/CVE-2025-5548
Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulner…
★ 2 · 2026-05-08
TheMalwareGuardian/CVE-2025-5548
Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.
★ 1 · 2026-03-23
JSantos1990/CVE-2025-5548
🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation, lab enviro…
★ 0 · 2026-03-18
CVSS 8.6 HIGH
CWE-611
Published 2026-10-01
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document.
The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error.
Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves.
Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.
Show 1 repositories
oscerd/CVE-2026-88789
Reproducer for CVE-2026-88789 (Apache Camel Quarkus camel-quarkus-support-xalan drops the JAXP external access restrictions, XXE / SSRF) — Camel Quarkus
★ 0 · 2026-10-01
PoCs 20
★ 31
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 8 of 20 repositories
kayl22/cve-2025-8110-GOGS-RCE
GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then trigge…
★ 4 · 2026-04-11
3jee/CVE-2025-8110
CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API
★ 2 · 2026-04-11
PoCs 6
★ 10
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 6 repositories
PoCs 3
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 3 repositories
suominen/dirtyah6
Tracking DirtyAH6 (CVE-2026-80844), the Linux kernel IPv6 AH routing-header out-of-bounds write
★ 0 · 2026-10-01
CVSS 9.1 CRITICAL
CWE-94
Published 2026-10-01
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The payload is planted during the unauthenticated booking flow and triggered when the Customer Cabinet block rendered by render_customer_dashboard() outputs the stored name into the content stream, where WordPress core's do_shortcode filter at priority 11 re-parses and executes it.
Show 1 repositories
murrez/CVE-2026-92966
CVE-2026-92966 — WordPress LatePoint ≤5.7.0 unauthenticated stored shortcode execution (CVSS 9.1, CWE-94). PoCbit mass-exploit PoC: plant [caption]/custom shor…
★ 0 · 2026-10-01
PoCs 7
★ 3
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 7 repositories
Ch4120N/CVE-2026-58138
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
★ 2 · 2026-07-15
CVSS 10.0 CRITICAL
CWE-94
Published 2026-09-30
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Show 1 repositories
murrez/CVE-2026-96349
CVE-2026-96349 — WordPress SiteSkite plugin ≤2.1.8 unauthenticated RCE (CVSS 10.0, CWE-94). PoCbit mass-exploit PoC: legacy API-key autologin (?token=) + REST …
★ 0 · 2026-10-01
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 7
★ 9
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 7 repositories
isagoakira/ghes-cve-scanner
GHES CVE Scanner — Defensive security tool for detecting CVE-2026-3854 (Git Push RCE) and CVE-2026-4821 (Management Console proxy injection) in GitHub …
★ 0 · 2026-05-05
PoCs 1
★ 0
Last push 2026-10-01 (1 week, 2 days ago)
Fetching description from NVD…
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.