Fetching description from NVD…
Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
Show 8 of 27 repositories
Langflow RCE
CVE-2026-33017 - An unauthenticated remote code execution in Langflow <= 1.8.1 via Public Flow Build Endpoint
CVE-2026-33017: Unauthenticated RCE in Langflow
Python POC, Exploit for CVE-2026-33017
CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated testing. Validate…
The vulnerability in Langflow 1.8.1 and earlier allows a remote, unauthenticated attacker to achieve arbitrary command execution on the host.
CVE-2026-33017 Exploit | by infrar3d
Fetching description from NVD…
Show 8 of 20 repositories
Proof of Concept for CVE-2025-31161 / CVE-2025-2825
🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit
CrushFTP CVE-2025-31161 Exploit Tool 🔓
PoC CVE-2025-31161 - Authentication Bypass CrushFTP
Official Nuclei template for CVE-2025-31161 (formerly CVE-2025-2825)
PoC Authentication Bypass to RCE to Exploit CVE-2025-31161
Fetching description from NVD…
Show 1 repositories
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.
Show 1 repositories
Fetching description from NVD…
Show 1 repositories
CVE-2026-72018
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Show 1 repositories
Authlib 1.7.2: Signature Verification Bypass - General JSON JWS Accepts Unsigned Payload when `signatures` is Empty
Fetching description from NVD…
Show 8 of 11 repositories
Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2 2.0.57: attack…
Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
CVE-2026-16723
Fastjson RCE
This is N-day patch we releasing by testing our model capabilities
fastjson jsontype利用
Fetching description from NVD…
Show 8 of 24 repositories
CVE-2025-30208-EXP
全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner
A PoC of the exploit script for the Arbitrary File Read vulnerability of Vite /@fs/ Path Traversal in the transformMiddleware (CVE-2025-30208).
CVE-2025-30208-EXP 任意文件读取
CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)
针对CVE-2025-30208和CVE-2025-31125的漏洞利用
CVE-2025-30208 - Vite Arbitrary File Read PoC
Fetching description from NVD…
Show 1 repositories
Local classroom demo of NoSQL operator injection in LangGraph's MongoDBSaver (GHSA-98xf-r82g-9mhx / CVE-2026-48121). Fictional data only.
Fetching description from NVD…
Show 3 repositories
POC exploit via unsafe `eval()` usage in Searchor (< 2.4.2)
Fetching description from NVD…
Show 7 repositories
wpDiscuz 7.0.4 Remote Code Execution
CVE-2020-24186的攻击脚本
WpDiscuz 7.0.4 Arbitrary File Upload Exploit
Fetching description from NVD…
Show 1 repositories
Docker lab for validating CVE-2026-84383 in libheif through Discourse
Fetching description from NVD…
Show 1 repositories
https://vuldb.com/cve/CVE-2026-102261
Fetching description from NVD…
Show 8 of 12 repositories
CVE-2026-34990 minimal PoC. CUPS <= 2.4.16 local privesc.
Generic PoC for CVE-2026-34990 - CUPS 2.4.16 Local Privilege Escalation via Local token disclosure and arbitrary root file overwrite.
LPE PoC for CVE-2026-34990 using a CUPS root file write vulnerability.
CVE-2026-34990 - OpenPrinting CUPS versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into authenticating to an attacker-controlled localhos…
CVE-2026-34990 - Draft or Todo
Fetching description from NVD…
Show 4 repositories
CVE-2026-41091
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM - via Cloud Files API + NTFS junction trickery. Forces De…
Windwos Zero Day Local PrivESc Exploit (CVE-2026-41091)
Scanner: CVE-2026-41091/45498 Microsoft Defender LPE/DoS — Python scanner for Windows Defender privilege escalation (CISA KEV)
Fetching description from NVD…
Show 8 of 14 repositories
Certighost POC
🛡️ Official AI Security Tool module for CVE-2026-54121 (Certighost - AD CS Domain Controller Impersonation & PKINIT Elevation).
CVE-2026-54121 - CertiGhost AD CS Multi-Exploit Framework | Rogue DC + LDAP spoofing, certificate abuse, PKINIT hash extraction, auto DCSync. Safe Checker + fu…
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. T…
CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
Fetching description from NVD…
Show 1 repositories
Sanitized UploadWizard report and patch verification notes for CVE-2026-100381.
Fetching description from NVD…
Show 1 repositories
Sanitized Wikibase report and patch verification notes for CVE-2026-100380.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Show 1 repositories
Sanitized Cargo report and patch verification notes for CVE-2026-96878.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Show 1 repositories
Sanitized Cargo report and patch verification notes for CVE-2026-96877.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Show 1 repositories
Sanitized Cargo report and patch verification notes for CVE-2026-96876.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Show 1 repositories
Sanitized Cargo report and patch verification notes for CVE-2026-96875.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.
Show 1 repositories
Sanitized Cargo report and patch verification notes for CVE-2026-96874.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0.
Show 1 repositories
Sanitized CirrusSearch report and patch verification notes for CVE-2026-96873.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.