Fetching description from NVD…
Show 1 repositories
Sanitized report and local PoC for CVE-2026-103584
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
Sanitized report and local PoC for CVE-2026-103584
Fetching description from NVD…
Security PoC payload host for CVE-2026-91159 oEmbed test (authorized bug bounty)
Fetching description from NVD…
CVE-2023-38831 winrar exploit generator
一款用于生成winrar程序RCE(即cve-2023-38831)的POC的工具。
An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23
lazy way to create CVE-2023-38831 winrar file for testing
CVE-2023-38831 PoC (Proof Of Concept)
Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)
Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.
This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading …
Fetching description from NVD…
EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103446
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103445
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103442
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103441
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103440
Fetching description from NVD…
Sanitized report summary and local PoC for CVE-2026-103437
Fetching description from NVD…
CVE-2026-12227 - Visual Composer <= 45.16.0 unauthenticated LFI via vcv-template (CVSS 9.8): Docker validation lab, safe-oracle PoC, nuclei template. Root caus…
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, a…
CVE-2026-12227 (CVSS 9.8): WordPress Visual Composer Website Builder ≤45.16.0 — unauthenticated local file inclusion via vcv-template. Educational PoC only.
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, a…
Fetching description from NVD…
CVE-2026-102427 is an unauthenticated remote code execution flaw in OrdaSoft Joomla Content Construction Kit (OS CCK) — Joomla component com_os_cck.
Fetching description from NVD…
CVE-2026-76570 PoC (PoCbit) — Joomla JCTables (com_jctables) <1.21.1: unauth SQL read/write via front-end JSON API getdatarow/getrow (CVSS 4.0 10.0 AT:N). chec…
Fetching description from NVD…
CVE-2025-59528 - FlowiseAI CustomMCP Remote Code Execution
CVE-2025-59528 Proof of Concept
A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also used in HTB s…
Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the /api/v1/node-load-method/customMCP endpoint…
CVE-2025-59528 Proof of Concept
Technical PoC for CVE-2025-59528 (Flowise < 3.0.5), demonstrating authenticated RCE through customMCP mcpServerConfig injection, with clear bilingual documenta…
Authenticated RCE PoC for Flowise version <= 3.0.5 via CustomMCP Node (CVE-2025-59528)
poc and yara rules
Fetching description from NVD…
CVE-2013-3660的x64 win7平台EXP源代码,成功率100%。
Fetching description from NVD…
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
Windows AppLocker Driver (appid.sys) LPE
Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
Fork of https://github.com/hakaioffsec/CVE-2024-21338
PoC for the Untrusted Pointer Dereference in the appid.sys driver
kcfg bypass example - CVE-2024-21338
The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.
Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.
Next.js RCE
Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC
CVE-2026-94545 - Draft or TODO
CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerabl…
Next.js next/og unauthenticated RCE (CVE-2026-94545) - PoC
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
CVE-2020-14008 - ManageEngine Applications Manager RCE
CVE-2020-14008 — ManageEngine Applications Manager Remote Code Execution
Fetching description from NVD…
Sanitized report and local PoC for CVE-2026-102975
Fetching description from NVD…
Sanitized report and local PoC for CVE-2026-102973
Fetching description from NVD…
Sanitized report and local PoC for CVE-2026-102971
Fetching description from NVD…
CVE-2023-20198 Exploit PoC
CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.
Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)
This is a webshell fingerprinting scanner designed to identify implants on Cisco IOS XE WebUI's affected by CVE-2023-20198 and CVE-2023-20273
CVE-2023-20198 & 0Day Implant Scanner
CVE-2023-20198 Checkscript
CVE-2023-20198 PoC (!)
A PoC for CVE 2023-20198
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.