Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
352PoC updated in 7 days
filters
11117 results
CVSS 2.9 LOW
CWE-280
Published 2026-09-23
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.
Show 1 repositories
PoCs 2
★ 18
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
Wh02m1/CVE-2026-78306
DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306
★ 18 · 2026-09-29
FEEDBEEF/Dji_ble_vuln
DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306
★ 0 · 2026-09-23
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-85520
CVE-2026-85520 PoC (PoCbit) — PrestaShop MyPresta gmfeed ≤2.3.9 unauthenticated arbitrary file write via feed.php (Save to file URL) → RCE. check + exploit + m…
★ 0 · 2026-09-29
CVSS 9.5 CRITICAL
CWE-119
Published 2026-09-27
PoCs 3
★ 13
Last push 2026-09-29 (1 week, 4 days ago)
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
Show 3 repositories
murrez/CVE-2026-88772
CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS…
★ 13 · 2026-09-27
PoCs 6
★ 28
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 6 repositories
remmons-r7/rapid7-CVE-2026-15409
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlan…
★ 28 · 2026-07-15
tc4dy/CVE-2026-15409-15410-Framework
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework - SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --prives…
★ 5 · 2026-09-29
Ch4120N/CVE-2026-15409
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as …
★ 3 · 2026-08-03
PoCs 2
★ 1
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
MRdark-ops/CVE-2026-8065
CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware …
★ 1 · 2026-09-29
murrez/CVE-2026-8065
CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware …
★ 0 · 2026-09-29
PoCs 32
★ 688
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 32 repositories
ThemeHackers/CVE-2024-38063
CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)
★ 44 · 2025-12-10
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
josemour8/CVE-2025-62023
s2Member (WordPress) Unauth RCE via SP Tracking Codes eval() + BONUS: incomplete-fix bypass — IPN notify vector still open in 251005..2512xx (fixed only in 2…
★ 0 · 2026-09-29
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 34
★ 73
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 8 of 34 repositories
hexsecteam/CVE-2025-8088-Winrar-Tool
A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header man…
★ 50 · 2025-09-04
jordan922/CVE-2025-8088
Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.
★ 10 · 2025-08-11
PoCs 2
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
PoCs 2
★ 1
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
murrez/CVE-2026-82901
CVE-2026-82901 PoC: WordPress Ultra Addons for Contact Form 7 ≤3.5.50 unauth file upload via signature field when PDF Generator is enabled → wp-content/uploads…
★ 1 · 2026-09-26
PoCs 1
★ 2
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 4
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
PoCs 3
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 3 repositories
Sushank05/mcp-doorman
A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of MCP servers…
★ 0 · 2026-09-29
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 2 repositories
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-101894
CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit…
★ 0 · 2026-09-29
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-101110
CVE-2026-101110 PoC: OrdaSoft Joomla Book Library (Free) <=6.4.6 unauth SQLi — field/direction ORDER BY, session prime + `-- xselect` blacklist bypass (com_boo…
★ 0 · 2026-09-29
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-101108
CVE-2026-101108 PoC: OrdaSoft Joomla Vehicle Manager (Free) <=6.5.7 unauth SQLi — order_field/order_direction unquoted ORDER BY (com_vehiclemanager). Colored c…
★ 0 · 2026-09-29
PoCs 1
★ 0
Last push 2026-09-29 (1 week, 4 days ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-100752
CVE-2026-100752 PoC: OrdaSoft Joomla Real Estate Manager (Free) <=6.7.8 unauth SQLi via order_field ORDER BY (com_realestatemanager). Colored check + mass expl…
★ 0 · 2026-09-29
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.