Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
CVE-2025-41249
CVE-2024-36774
CVE-2022-21812
8 contacts in last 24h
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
11105 results
PoCs 12
★ 134
Last push 2026-10-09 (18 hours, 53 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 31
★ 358
Last push 2026-10-09 (18 hours, 53 minutes ago)
Fetching description from NVD…
Show 8 of 31 repositories
horizon3ai/CVE-2022-40684
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
★ 358 · 2022-10-13
PoCs 14
★ 253
Last push 2026-10-09 (18 hours, 53 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
jpiechowka/at-doom-fortigate
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
★ 5 · 2024-01-23
PoCs 2
★ 144
Last push 2026-10-09 (19 hours ago)
Fetching description from NVD…
Show 2 repositories
rkrakesh524/oob_entry
oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. 🐙
★ 0 · 2026-10-09
PoCs 3
★ 7
Last push 2026-10-09 (19 hours, 36 minutes ago)
Fetching description from NVD…
Show 3 repositories
Xewdy444/Netgrave
A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)
★ 7 · 2026-10-09
PoCs 12
★ 231
Last push 2026-10-09 (20 hours, 5 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
HydraSoft/CVE-2026-41089-Netlogon-RCE
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …
★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…
★ 14 · 2026-06-04
hnytgl/CVE-2026-41089
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
★ 13 · 2026-09-26
ZeroDayVPN/CVE-2026-41089-Netlogon
🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…
★ 5 · 2026-09-29
PoCs 4
★ 16
Last push 2026-10-09 (20 hours, 10 minutes ago)
Fetching description from NVD…
Show 4 repositories
shinthink/CVE-2026-57827
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
★ 16 · 2026-07-29
Candisexterior171/CVE-2026-57827
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
★ 0 · 2026-10-09
PoCs 11
★ 7
Last push 2026-10-09 (20 hours, 10 minutes ago)
Fetching description from NVD…
Show 8 of 11 repositories
everest90909/YellowKey-WinRE-Remediation
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…
★ 1 · 2026-05-21
PoCs 7
★ 154
Last push 2026-10-09 (20 hours, 12 minutes ago)
Fetching description from NVD…
Show 7 repositories
mpgn/CVE-2019-7238
🐱💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱💻
★ 154 · 2019-02-25
PoCs 33
★ 289
Last push 2026-10-09 (20 hours, 12 minutes ago)
Fetching description from NVD…
Show 8 of 33 repositories
PoCs 8
★ 13
Last push 2026-10-09 (20 hours, 14 minutes ago)
Fetching description from NVD…
Show 8 repositories
PoCs 40
★ 12
Last push 2026-10-09 (20 hours, 15 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …
★ 12 · 2026-06-14
luiskrnr/exploit-CVE-2026-23744
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…
★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …
★ 3 · 2026-08-11
ctzisme/CVE-2026-23744
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
★ 1 · 2026-03-26
PoCs 325
★ 4074
Last push 2026-10-09 (20 hours, 16 minutes ago)
Fetching description from NVD…
Show 8 of 325 repositories
tgies/copy-fail-c
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
★ 445 · 2026-07-17
painoob/Copy-Fail-Exploit-CVE-2026-31431
Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …
★ 109 · 2026-04-29
sgkdev/page_inject
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
★ 76 · 2026-05-06
PoCs 3
★ 1
Last push 2026-10-09 (20 hours, 22 minutes ago)
Fetching description from NVD…
Show 3 repositories
Jvr2022/CVE-2026-31802
PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.
★ 1 · 2026-03-14
CVSS 9.8 CRITICAL
CWE-89
Published 2017-02-17
PoCs 1
★ 0
Last push 2026-10-09 (20 hours, 33 minutes ago)
Discovered 2026-10-09 03:16
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
Show 1 repositories
PoCs 42
★ 66
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 42 repositories
hannob/webminex
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
★ 8 · 2019-12-25
PoCs 37
★ 4291
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 37 repositories
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…
★ 4291 · 2021-04-04
adm1in/CodeTest
CodeTest信息收集和漏洞利用工具,可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作,漏洞利用模块可选择需要测试的漏洞模块,或者选择所有模块测试,包含CVE-2020-14882, CVE-2020-2555等,可自己收集脚本后按照模板进行修改。
★ 13 · 2020-12-29
PoCs 30
★ 515
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 30 repositories
shack2/javaserializetools
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
★ 515 · 2020-10-01
Cymmetria/weblogic_honeypot
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote …
★ 33 · 2020-04-25
PoCs 2
★ 1
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 2 repositories
PoCs 9
★ 28
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 9 repositories
PoCs 40
★ 422
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
tpt11fb/AttackTomcat
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
★ 257 · 2022-11-15
PoCs 18
★ 295
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 18 repositories
tpt11fb/AttackTomcat
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
★ 257 · 2022-11-15
PoCs 4
★ 4
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 4 repositories
PoCs 15
★ 113
Last push 2026-10-09 (20 hours, 33 minutes ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 99
★ 376
Last push 2026-10-09 (20 hours, 34 minutes ago)
Fetching description from NVD…
Show 8 of 99 repositories
tpt11fb/SpringVulScan
burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977
★ 155 · 2023-01-23
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.