Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
355PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103584

Sanitized report and local PoC for CVE-2026-103584

★ 0 · 2026-10-01
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
sl4x0/autheo-cve-2026-91159-poc

Security PoC payload host for CVE-2026-91159 oEmbed test (authorized bug bounty)

★ 0 · 2026-09-30
CVE-2023-38831
HOTMULTI PoC
PoCs 60 ★ 783 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 8 of 60 repositories
b1tg/CVE-2023-38831-winrar-exploit

CVE-2023-38831 winrar exploit generator

★ 783 · 2023-11-26
Garck3h/cve-2023-38831

一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。

★ 126 · 2023-08-27
ignis-sec/CVE-2023-38831-RaRCE

An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23

★ 113 · 2023-08-27
BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc

lazy way to create CVE-2023-38831 winrar file for testing

★ 91 · 2023-08-24
HDCE-inc/CVE-2023-38831

CVE-2023-38831 PoC (Proof Of Concept)

★ 89 · 2024-08-04
knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831

Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)

★ 40 · 2023-08-28
Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE

Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.

★ 22 · 2023-08-31
xaitax/WinRAR-CVE-2023-38831

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …

★ 17 · 2023-09-08
PoCs 1 ★ 2 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
ShadowForge-Cyber/CVE-2026-76504-Proof-of-concept

EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)

★ 2 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103446

Sanitized report summary and local PoC for CVE-2026-103446

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103445

Sanitized report summary and local PoC for CVE-2026-103445

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103442

Sanitized report summary and local PoC for CVE-2026-103442

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103441

Sanitized report summary and local PoC for CVE-2026-103441

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103440

Sanitized report summary and local PoC for CVE-2026-103440

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-103437

Sanitized report summary and local PoC for CVE-2026-103437

★ 0 · 2026-09-30
PoCs 4 ★ 1 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 4 repositories
Hassham1/CVE-2026-12227-visualcomposer-lfi-poc

CVE-2026-12227 - Visual Composer <= 45.16.0 unauthenticated LFI via vcv-template (CVSS 9.8): Docker validation lab, safe-oracle PoC, nuclei template. Root caus…

★ 1 · 2026-09-24
be-keb/CVE-2026-12227

CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, a…

★ 1 · 2026-09-27
murrez/CVE-2026-12227

CVE-2026-12227 (CVSS 9.8): WordPress Visual Composer Website Builder ≤45.16.0 — unauthenticated local file inclusion via vcv-template. Educational PoC only.

★ 0 · 2026-09-24
MRdark-ops/CVE-2026-12227

CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, a…

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-102427

CVE-2026-102427 is an unauthenticated remote code execution flaw in OrdaSoft Joomla Content Construction Kit (OS CCK) — Joomla component com_os_cck.

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-76570

CVE-2026-76570 PoC (PoCbit) — Joomla JCTables (com_jctables) <1.21.1: unauth SQL read/write via front-end JSON API getdatarow/getrow (CVSS 4.0 10.0 AT:N). chec…

★ 0 · 2026-09-30
CVE-2025-59528
MULTI PoC
PoCs 13 ★ 1 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
UsifAraby/CVE-2025-59528-POC

CVE-2025-59528 - FlowiseAI CustomMCP Remote Code Execution

★ 1 · 2026-04-13
vanhari/CVE-2025-59528

CVE-2025-59528 Proof of Concept

★ 1 · 2026-04-13
maradonam18/-CVE-2025-59528-PoC

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also used in HTB s…

★ 1 · 2026-04-15
arensballiu/Flowise-RCE-CVE-2025-59528

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the /api/v1/node-load-method/customMCP endpoint…

★ 1 · 2026-09-28
mananispiwpiw/CVE-2025-59528-PoC

CVE-2025-59528 Proof of Concept

★ 1 · 2026-05-08
NymiiTechTips/CVE-2025-59528

Technical PoC for CVE-2025-59528 (Flowise < 3.0.5), demonstrating authenticated RCE through customMCP mcpServerConfig injection, with clear bilingual documenta…

★ 1 · 2026-05-16
corey-farley/CVE-2025-59528-Flowise-RCE

Authenticated RCE PoC for Flowise version <= 3.0.5 via CustomMCP Node (CVE-2025-59528)

★ 1 · 2026-05-17
PoCs 2 ★ 3 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 2 repositories
ExploitCN/CVE-2013-3660-x64-WIN7

CVE-2013-3660的x64 win7平台EXP源代码,成功率100%。

★ 3 · 2022-04-09
kikozz/CVE-2013-3660-win32k.sys
★ 0 · 2026-09-30
CVE-2024-21338
HOTMULTI PoC
PoCs 9 ★ 332 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 9 repositories
hakaioffsec/CVE-2024-21338

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 332 · 2024-04-16
Crowdfense/CVE-2024-21338

Windows AppLocker Driver (appid.sys) LPE

★ 81 · 2024-07-29
tykawaii98/CVE-2024-21338_PoC
★ 40 · 2024-06-23
Zombie-Kaiser/CVE-2024-21338-x64-build-

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

★ 7 · 2024-05-22
MistyFir/CVE-2024-21338-Exploit
★ 7 · 2026-04-06
UMU618/CVE-2024-21338

Fork of https://github.com/hakaioffsec/CVE-2024-21338

★ 2 · 2024-04-17
wusijie/CVE-2024-21338-1

PoC for the Untrusted Pointer Dereference in the appid.sys driver

★ 2 · 2024-05-05
hackyboiz/kcfg-bypass

kcfg bypass example - CVE-2024-21338

★ 2 · 2025-01-12
CVSS 7.2 HIGH CWE-79 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.

Show 1 repositories
JailBr3ak/CVE-2026-97347
★ 0 · 2026-09-30
CVE-2026-94545
MULTI PoC
CVSS 5.3 MEDIUM CWE-116 Published 2026-09-30 PoCs 5 ★ 49 Last push 2026-09-30 (1 week, 3 days ago)

Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.

Show 5 repositories
EQSTLab/CVE-2026-94545

Next.js RCE

★ 49 · 2026-09-29
mhtsec/CVE-2026-94545

Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC

★ 2 · 2026-09-30
HORKimhab/CVE-2026-94545

CVE-2026-94545 - Draft or TODO

★ 1 · 2026-09-23
Hassham1/CVE-2026-94545-nextjs-og-poc

CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerabl…

★ 1 · 2026-09-23
MRdark-ops/CVE-2026-94545-

Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC

★ 1 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 3 ★ 5 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 3 repositories
JackHars/cve-2020-14008
★ 5 · 2025-05-26
0x0d3ad/CVE-2020-14008

CVE-2020-14008 - ManageEngine Applications Manager RCE

★ 4 · 2026-05-09
raflesiait/CVE-2020-14008_ManageEngine

CVE-2020-14008 — ManageEngine Applications Manager Remote Code Execution

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-102975

Sanitized report and local PoC for CVE-2026-102975

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-102973

Sanitized report and local PoC for CVE-2026-102973

★ 0 · 2026-09-30
PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-102971

Sanitized report and local PoC for CVE-2026-102971

★ 0 · 2026-09-30
CVE-2023-20198
MULTI PoC
PoCs 35 ★ 66 Last push 2026-09-30 (1 week, 3 days ago)

Fetching description from NVD…

Show 8 of 35 repositories
smokeintheshell/CVE-2023-20198

CVE-2023-20198 Exploit PoC

★ 66 · 2026-03-26
W01fh4cker/CVE-2023-20198-RCE

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.

★ 43 · 2024-04-25
fox-it/cisco-ios-xe-implant-detection

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

★ 41 · 2026-09-30
Shadow0ps/CVE-2023-20198-Scanner

This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273

★ 33 · 2023-10-24
ZephrFish/CVE-2023-20198-Checker

CVE-2023-20198 & 0Day Implant Scanner

★ 32 · 2026-07-30
Atea-Redteam/CVE-2023-20198

CVE-2023-20198 Checkscript

★ 20 · 2023-10-23
Tounsi007/CVE-2023-20198

CVE-2023-20198 PoC (!)

★ 11 · 2023-10-17
Pushkarup/CVE-2023-20198

A PoC for CVE 2023-20198

★ 8 · 2023-10-23
< Prev Page 18 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.