Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
355PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVE-2026-90817
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-73, CWE-94 Published 2026-09-20 PoCs 5 ★ 2 Last push 2026-10-01 (1 week, 2 days ago)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.

Show 5 repositories
murrez/CVE-2026-90817

Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation.

★ 2 · 2026-09-21
yulisec/CVE-2026-90817
★ 1 · 2026-09-24
securifera/CVE-2026-90817

REDCap DataImport RCE

★ 1 · 2026-10-01
ExDev994/CVE-2026-90817
★ 0 · 2026-09-21
Farih123/CVE-2026-90817
★ 0 · 2026-09-26
CVSS 6.9 MEDIUM CWE-639 Published 2026-09-29 PoCs 1 ★ 1 Last push 2026-10-01 (1 week, 2 days ago)

Joomla! Core - [20260902] - Core - Unauthorized user account creation via profile.save controller in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.

Show 1 repositories
aorozco-sys/CVE-2026-90907

CVE-2026-90907 (CVSS 6.9) — Joomla! CMS unauthorized user account creation via com_users profile.save (authorization bypass). Non-destructive checker + authori…

★ 1 · 2026-10-01
CVE-2024-21626
MULTI PoC
PoCs 19 ★ 80 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 19 repositories
NitroCao/CVE-2024-21626

PoC and Detection for CVE-2024-21626

★ 80 · 2024-02-06
V0WKeep3r/CVE-2024-21626-runcPOC
★ 6 · 2024-02-05
cdxiaodong/CVE-2024-21626

CVE-2024-21626-poc-research-Reappearance-andtodo

★ 5 · 2024-02-02
zhangguanzhang/CVE-2024-21626
★ 4 · 2024-02-02
laysakura/CVE-2024-21626-demo

Container Runtime Meetup #5 のLT用のデモ

★ 3 · 2024-02-02
Sk3pper/CVE-2024-21626
★ 2 · 2024-11-10
KubernetesBachelor/CVE-2024-21626

POC

★ 2 · 2025-05-27
dorser/cve-2024-21626
★ 2 · 2024-04-16
CVE-2023-28432
MULTI PoC
PoCs 20 ★ 37 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 20 repositories
MzzdToT/CVE-2023-28432

MinIO敏感信息泄露漏洞批量扫描poc&exp

★ 37 · 2023-03-24
Mr-xn/CVE-2023-28432

CVE-2023-28434 nuclei templates

★ 34 · 2023-03-23
acheiii/CVE-2023-28432

CVE-2023-28432 POC

★ 15 · 2023-03-24
Chocapikk/CVE-2023-28432

Automated vulnerability scanner for CVE-2023-28432 in Minio deployments, revealing sensitive environment variables.

★ 11 · 2026-01-08
gobysec/CVE-2023-28432

MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)

★ 10 · 2023-03-24
Cuerz/CVE-2023-28432

CVE-2023-28432 MinIO敏感信息泄露检测脚本

★ 10 · 2023-03-29
Okaytc/minio_unauth_check

CVE-2023-28432,minio未授权访问检测工具

★ 7 · 2023-03-24
yTxZx/CVE-2023-28432
★ 3 · 2023-10-20
CVE-2026-93616
CRITICAL
CVSS 9.8 CRITICAL CWE-22 Published 2026-09-22 PoCs 2 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Show 2 repositories
WadesWeaponShed/CVE-2026-93616_Checks

Simple Checks to look for indicators of compromise

★ 0 · 2026-09-22
BishopFox/CVE-2026-93616-check

Safely detect Check Point CPM RCE CVE-2026-93616

★ 0 · 2026-10-01
PoCs 3 ★ 1 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 3 repositories
CEAarab/CVE-2026-26026-PoC
★ 1 · 2026-04-22
petriQore/CVE-2026-26026_PoC

PoC script for CVE-2026-26026 GLPI versions 11.0.0 through 11.0.5

★ 0 · 2026-10-01
CVSS 6.1 MEDIUM CWE-79 Published 2026-09-25 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on forms whose admin-authored confirmation message places the {page_title} Smart Tag inside an HTML attribute context.

Show 1 repositories
dorkerdevil/wpforms-xss-fix-bypass

Unauthenticated reflected XSS in WPForms <= 2.0.2.1 — bypass of the CVE-2026-88996 Smart Tag escaping at attribute-name position

★ 0 · 2026-10-01
CVE-2024-3094
HOTMULTI PoC
PoCs 84 ★ 3551 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 84 repositories
amlweems/xzbot

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

★ 3551 · 2024-04-03
lockness-Ko/xz-vulnerable-honeypot

An ssh honeypot with the XZ backdoor. CVE-2024-3094

★ 146 · 2024-04-02
FabioBaroni/CVE-2024-3094-checker

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

★ 72 · 2024-03-31
robertdfrench/ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

★ 60 · 2026-09-25
byinarie/CVE-2024-3094-info

Information for CVE-2024-3094

★ 54 · 2024-04-01
jfrog/cve-2024-3094-tools
★ 44 · 2024-04-07
gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer

Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be v…

★ 26 · 2024-04-07
0xlane/xz-cve-2024-3094

XZ Backdoor Extract(Test on Ubuntu 23.10)

★ 17 · 2024-04-02
CVE-2025-24813
HOTMULTI PoC
PoCs 58 ★ 195 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 58 repositories
absholi7ly/POC-CVE-2025-24813

his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tom…

★ 195 · 2025-03-14
iSee857/CVE-2025-24813-PoC

Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)

★ 98 · 2025-04-02
drcrypterdotru/Apache-GOExploiter

Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast

★ 20 · 2025-10-05
mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-

Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)

★ 19 · 2025-05-25
charis3306/CVE-2025-24813

CVE-2025-24813利用工具

★ 16 · 2025-03-16
qzy0x/cve-2025-24813_poc

cve-2025-24813验证脚本

★ 11 · 2025-03-14
Franconyu/Poc_for_CVE-2025-24813

CVE-2025-24813 poc

★ 9 · 2025-04-11
x00byte/PutScanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

★ 9 · 2025-07-19
PoCs 2 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 2 repositories
murrez/CVE-2026-102425

CVE-2026-102425 PoC (PoCbit) — Joomla Balbooa Forms (com_baforms) <2.4.3.4 unauth RCE via field shortcode injection in post-submission PHP eval(). check + expl…

★ 0 · 2026-09-30
tonydelouvre/CVE-2026-102425

CVE-2026-102425 - GUI CONSOLE

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
Rollingzzzzz/heif-heist-lab

HEIF Heist lab — reproduce the Meta $115K HEIC upload bug (CVE-2025-46087) in Docker: crafted HEIC → heap disclosure → admin secrets leak into your profile pic…

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
TeamN4C/SG-2026-0026

CVE-2026-62146 CRI-O ShmPath poisoning PoC and exploit

★ 0 · 2026-10-01
CVE-2017-0144
HOTMULTI PoC
PoCs 25 ★ 339 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 25 repositories
peterpt/eternal_scanner

An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)

★ 339 · 2024-07-31
AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint

This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a…

★ 15 · 2025-07-10
AtithKhawas/autoblue

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF …

★ 5 · 2024-12-30
sethwhy/BlueDoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privilege…

★ 2 · 2024-12-22
0xBlackash/CVE-2017-0144

CVE-2017-0144

★ 2 · 2026-06-14
kimocoder/eternalblue

CVE-2017-0144

★ 1 · 2024-04-01
MedX267/EternalBlue-Vulnerability-Scanner

This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.

★ 1 · 2025-02-03
CVE-2025-5548
MULTI PoC
PoCs 30 ★ 2 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 30 repositories
mk017-hk/CVE-2025-5548

Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository documents vulner…

★ 2 · 2026-05-08
TheMalwareGuardian/CVE-2025-5548

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

★ 1 · 2026-03-23
JSantos1990/CVE-2025-5548

🚀 Complete analysis and exploitation of CVE-2025-5548 (FreeFloat FTP Server 1.0 - NOOP Buffer Overflow) Full methodology: manual tool installation, lab enviro…

★ 0 · 2026-03-18
alanschmidt81/CVE-2025-5548
★ 0 · 2026-03-15
javyan05/CVE-2025-5548

Entorno y explotación de la vulnerabilidad CVE-2025-5548

★ 0 · 2026-03-16
charlyrr/CVE-2025-5548
★ 0 · 2026-03-18
celiagomezserra/CVE-2025-5548

Explotación de la vulnerabilidad CVE-2025-5548, paso a paso

★ 0 · 2026-03-19
CVSS 8.6 HIGH CWE-611 Published 2026-10-01 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.

Show 1 repositories
oscerd/CVE-2026-88789

Reproducer for CVE-2026-88789 (Apache Camel Quarkus camel-quarkus-support-xalan drops the JAXP external access restrictions, XXE / SSRF) — Camel Quarkus

★ 0 · 2026-10-01
CVE-2025-8110
MULTI PoC
PoCs 20 ★ 31 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 20 repositories
zAbuQasem/gogs-CVE-2025-8110

CVE-2025-8110 PoC

★ 31 · 2025-12-24
rxerium/CVE-2025-8110

Detection template for CVE-2025-8110

★ 22 · 2025-12-11
Ghxstsec/CVE-2025-8110
★ 5 · 2026-04-20
joaquinrrr/CVE-2025-8110

PoC exploit for CVE-2025-8110

★ 5 · 2026-06-25
kayl22/cve-2025-8110-GOGS-RCE

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and then trigge…

★ 4 · 2026-04-11
Shirouuu/CVE-2025-8110-gogs-poc

PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink

★ 4 · 2026-07-17
3jee/CVE-2025-8110

CVE-2025-8110 — Gogs <= 0.13.3 Arbitrary File Write via Symlink Traversal in PutContents API

★ 2 · 2026-04-11
CVE-2026-33825
MULTI PoC
PoCs 6 ★ 10 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 6 repositories
Letlaka/redsun-bluehammer-undefend-detection-pack

Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.

★ 10 · 2026-05-05
0xBlackash/CVE-2026-33825

CVE-2026-33825

★ 8 · 2026-05-20
Joe1sn/CVE-2026-33825

RedSun PoC for self use

★ 3 · 2026-05-02
Bilal3755/Detecting_blue_hammer_vuln

Threat hunting query for bluehammer CVE windows CVE-2026-33825

★ 0 · 2026-04-20
kaleth4/CVE-2026-33825
★ 0 · 2026-04-22
anasabugaddara-ux/defender-bluehammer-audit

Defensive Metasploit post module for CVE-2026-33825 (BlueHammer): Defender version/posture detection + compromise-hunt. Detection only.

★ 0 · 2026-10-01
PoCs 3 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 3 repositories
suominen/dirtyah6

Tracking DirtyAH6 (CVE-2026-80844), the Linux kernel IPv6 AH routing-header out-of-bounds write

★ 0 · 2026-10-01
0xBlackash/CVE-2026-80844

CVE-2026-80844

★ 0 · 2026-09-28
HORKimhab/CVE-2026-80844

CVE-2026-80844, DirtyAH6

★ 0 · 2026-09-21
CVE-2026-92966
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-10-01 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The payload is planted during the unauthenticated booking flow and triggered when the Customer Cabinet block rendered by render_customer_dashboard() outputs the stored name into the content stream, where WordPress core's do_shortcode filter at priority 11 re-parses and executes it.

Show 1 repositories
murrez/CVE-2026-92966

CVE-2026-92966 — WordPress LatePoint ≤5.7.0 unauthenticated stored shortcode execution (CVSS 9.1, CWE-94). PoCbit mass-exploit PoC: plant [caption]/custom shor…

★ 0 · 2026-10-01
CVE-2026-58138
MULTI PoC
PoCs 7 ★ 3 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-58138

CVE-2026-58138

★ 3 · 2026-09-05
Ch4120N/CVE-2026-58138

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

★ 2 · 2026-07-15
BiiTts/CVE-2026-58138-Conductor-Unauth-RCE

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

★ 0 · 2026-06-30
seqra/cve-2026-58138
★ 0 · 2026-07-15
0xgh057r3c0n/CVE-2026-58138

CVE-2026-58138 - Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator

★ 0 · 2026-07-22
Procjevt/CVE-2026-58138
★ 0 · 2026-07-27
Ez4rd1x1/CVE-2026-58138-Research

critical-severity unauthenticated Remote Code Execution (RCE) vulnerability impacting Orkes Conductor

★ 0 · 2026-10-01
CVE-2026-96349
CRITICAL
CVSS 10.0 CRITICAL CWE-94 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.

Show 1 repositories
murrez/CVE-2026-96349

CVE-2026-96349 — WordPress SiteSkite plugin ≤2.1.8 unauthenticated RCE (CVSS 10.0, CWE-94). PoCbit mass-exploit PoC: legacy API-key autologin (?token=) + REST …

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
rimbadirgantara/CVE-2026-48500
★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
Cr0wld3r/CVE-2026-11318

Local Privilege Escalation (LPE) Vulnerabilities in DeskIn macOS Client

★ 0 · 2026-10-01
CVE-2026-3854
MULTI PoC
PoCs 7 ★ 9 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 7 repositories
royaleybovich/CVE-2026-3854-lab
★ 9 · 2026-10-01
lysophavin18/CVE-2026-3854-PoC

GitHub RCE via X-Stat Push Option Injection

★ 2 · 2026-04-29
5kr1pt/CVE-2026-3854
★ 0 · 2026-04-28
LACHHAB-Anas/Exploit_CVE-2026-3854

Details about CVE-2026-3854

★ 0 · 2026-04-28
simondankelmann/cve-2026-3854-test

CVE-2026-3854 patch bypass testing

★ 0 · 2026-04-29
isagoakira/ghes-cve-scanner

GHES CVE Scanner — Defensive security tool for detecting CVE-2026-3854 (Git Push RCE) and CVE-2026-4821 (Management Console proxy injection) in GitHub …

★ 0 · 2026-05-05
ridhinva/ghe-push-option-rce-scanner

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

★ 0 · 2026-08-07
PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103585

Sanitized report and local PoC for CVE-2026-103585

★ 0 · 2026-10-01
< Prev Page 17 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.