Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
352PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVSS 2.9 LOW CWE-280 Published 2026-09-23 PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.

Show 1 repositories
BomboBombone/CVE-2026-96872

Sanitized WikiLambda report and patch verification notes for CVE-2026-96872.

★ 0 · 2026-09-29
PoCs 2 ★ 18 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
Wh02m1/CVE-2026-78306

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

★ 18 · 2026-09-29
FEEDBEEF/Dji_ble_vuln

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

★ 0 · 2026-09-23
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-85520

CVE-2026-85520 PoC (PoCbit) — PrestaShop MyPresta gmfeed ≤2.3.9 unauthenticated arbitrary file write via feed.php (Save to file URL) → RCE. check + exploit + m…

★ 0 · 2026-09-29
CVE-2026-88772
CRITICAL
CVSS 9.5 CRITICAL CWE-119 Published 2026-09-27 PoCs 3 ★ 13 Last push 2026-09-29 (1 week, 4 days ago)

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Show 3 repositories
murrez/CVE-2026-88772

CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS…

★ 13 · 2026-09-27
FollowerSeize/CVE-2026-88772-POC

CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)

★ 0 · 2026-09-28
CVE-2026-15409
MULTI PoC
PoCs 6 ★ 28 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 6 repositories
remmons-r7/rapid7-CVE-2026-15409

This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlan…

★ 28 · 2026-07-15
tc4dy/CVE-2026-15409-15410-Framework

CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework - SSRF→Erlang RPC→RCE→root privesc. Features: --detect safe check, --exec, --read-file, --prives…

★ 5 · 2026-09-29
0xBlackash/CVE-2026-15409

CVE-2026-15409

★ 3 · 2026-07-15
Ch4120N/CVE-2026-15409

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as …

★ 3 · 2026-08-03
HORKimhab/CVE-2026-15409

CVE-2026-15409 - Dectect

★ 0 · 2026-07-15
MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check

Unofficial Bash IoC checker for SonicWall SMA1000 appliances affected by actively exploited CVE-2026-15409 and CVE-2026-15410.

★ 0 · 2026-07-16
PoCs 2 ★ 1 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
MRdark-ops/CVE-2026-8065

CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware …

★ 1 · 2026-09-29
murrez/CVE-2026-8065

CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware …

★ 0 · 2026-09-29
CVE-2024-38063
HOTMULTI PoC
PoCs 32 ★ 688 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 32 repositories
ynwarcs/CVE-2024-38063

poc for CVE-2024-38063 (RCE in tcpip.sys)

★ 688 · 2024-08-27
Sachinart/CVE-2024-38063-poc

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

★ 86 · 2024-08-28
ThemeHackers/CVE-2024-38063

CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)

★ 44 · 2025-12-10
patchpoint/CVE-2024-38063
★ 20 · 2024-08-27
diegoalbuquerque/CVE-2024-38063

mitigation script by disabling ipv6 of all interfaces

★ 13 · 2024-08-15
zenzue/CVE-2024-38063-POC

potential memory corruption vulnerabilities in IPv6 networks.

★ 7 · 2024-08-28
PumpkinBridge/Windows-CVE-2024-38063

Windows TCP/IP IPv6(CVE-2024-38063)

★ 4 · 2024-08-28
thanawee321/CVE-2024-38063

Vulnerability CVE-2024-38063

★ 3 · 2024-10-18
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
josemour8/CVE-2025-62023

s2Member (WordPress) Unauth RCE via SP Tracking Codes eval() + BONUS: incomplete-fix bypass — IPN notify vector still open in 251005..2512xx (fixed only in 2…

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
flenz00/CVE-2026-18110-PoC

Proof-of-Concept for CVE-2026-18110

★ 0 · 2026-09-29
CVE-2025-8088
MULTI PoC
PoCs 34 ★ 73 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 34 repositories
sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-

CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit)

★ 73 · 2025-08-13
onlytoxi/CVE-2025-8088-Winrar-Tool

Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088

★ 55 · 2025-08-18
hexsecteam/CVE-2025-8088-Winrar-Tool

A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header man…

★ 50 · 2025-09-04
knight0x07/WinRAR-CVE-2025-8088-PoC-RAR

WinRAR 0day CVE-2025-8088 PoC RAR Archive

★ 44 · 2025-08-12
pentestfunctions/CVE-2025-8088-Multi-Document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

★ 35 · 2025-08-17
aldisakti2/CVE-2025-8088-BUILDER-Winrar-Tool

CVE-2025-8088-BUILDER

★ 28 · 2025-10-20
AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal

An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist.

★ 12 · 2025-08-26
jordan922/CVE-2025-8088

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

★ 10 · 2025-08-11
PoCs 2 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
xs2024770/CVE-2024-57521-RuoYi-SQLi

Description: CVE-2024-57521 RuoYi SQL 注入漏洞代码审计、%0b 绕过与自动化 PoC

★ 0 · 2026-09-29
PoCs 2 ★ 1 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
murrez/CVE-2026-82901

CVE-2026-82901 PoC: WordPress Ultra Addons for Contact Form 7 ≤3.5.50 unauth file upload via signature field when PDF Generator is enabled → wp-content/uploads…

★ 1 · 2026-09-26
tonydelouvre/CVE-2026-82901

CVE-2026-82901 — Ultra Addons for Contact Form 7 Mass Exploiter (GUI + CLI)

★ 0 · 2026-09-29
PoCs 1 ★ 2 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
EQSTLab/CVE-2026-6951

simple-git RCE

★ 2 · 2026-09-29
PoCs 2 ★ 4 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
EQSTLab/CVE-2026-49869

Kestra Unauthenticated RCE

★ 4 · 2026-09-29
Ap0dexMe0/CVE-2026-49869

Kestra Auth-Bypass Vulnerability Checker

★ 3 · 2026-06-30
PoCs 3 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 3 repositories
PRE5T0/CVE-2025-54136

CVE-2025-54136 PoC

★ 0 · 2026-01-15
Sushank05/mcp-doorman

A lightweight mcp to prevent poisoning CVE (CVE-2025-54136), researchers hijacking Claude Code/Copilot/Gemini via prompt injection, and hundreds of MCP servers…

★ 0 · 2026-09-29
GeeksikhSecurity/ai-tool-poisoning-guard

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03, CVE-2025-54136).

★ 0 · 2026-09-24
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
InertFluid/cve-2026-61732-lab

Benign, self-contained reproduction of CVE-2026-61732 (Decepticon ChatML role-boundary forgery)

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-10817

CVE-2026-10817

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
dpfkdlemtp/CVE-2021-43718

Published Epson EH-TW5350 CVE · Web Control authentication bypass · B-BEAM-BOB team

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
dpfkdlemtp/CVE-2021-43717

Published Epson EH-TW5350 CVE · Hard-coded credentials · B-BEAM-BOB team

★ 0 · 2026-09-29
PoCs 2 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
dpfkdlemtp/epson-eh-tw5350-advisories

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

★ 0 · 2026-09-29
dpfkdlemtp/CVE-2021-43716

Published Epson EH-TW5350 CVE · Firmware update verification bypass · B-BEAM-BOB team

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
dpfkdlemtp/CVE-2026-100633

Published SiYuan CVE · Reporter: dpfkdlemtp · Official record and advisory links

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-101894

CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit…

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-101110

CVE-2026-101110 PoC: OrdaSoft Joomla Book Library (Free) <=6.4.6 unauth SQLi — field/direction ORDER BY, session prime + `-- xselect` blacklist bypass (com_boo…

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-101108

CVE-2026-101108 PoC: OrdaSoft Joomla Vehicle Manager (Free) <=6.5.7 unauth SQLi — order_field/order_direction unquoted ORDER BY (com_vehiclemanager). Colored c…

★ 0 · 2026-09-29
PoCs 1 ★ 0 Last push 2026-09-29 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-100752

CVE-2026-100752 PoC: OrdaSoft Joomla Real Estate Manager (Free) <=6.7.8 unauth SQLi via order_field ORDER BY (com_realestatemanager). Colored check + mass expl…

★ 0 · 2026-09-29
< Prev Page 20 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.