Fetching description from NVD…
Show 1 repositories
PoC for CVE-2020-13664
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
PoC for CVE-2020-13664
Fetching description from NVD…
Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_fil…
Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup
Fetching description from NVD…
CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE
CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell ge…
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution
PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git objects. Edu…
HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and…
Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)
Automated exploit for Krayin CRM ≤ 2.2.x.
A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x
Fetching description from NVD…
Proof of concept for CVE-2026-43786, a local privilege escalation vulnerability in macOS CoreServices that allows an application to gain root privileges.
CVE-2026-43786
Fetching description from NVD…
CVE-2026-6471
postgres CVE-2026-6471 Exploit
Fetching description from NVD…
CVE-2026-5054
Fetching description from NVD…
CVE-2026-5053
Fetching description from NVD…
CVE-2026-41651 — PackageKit TOCTOU LPE
CVE-2026-41651
Poc for Pack2TheRoot CVE-2026-41651
CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation
Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)
Fetching description from NVD…
CVE-2026-75604 Next.js Windows RCE poc
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilitie…
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.
Fetching description from NVD…
Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.
PoC for CVE-2026-20817
Fetching description from NVD…
Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandb…
eprocess offset puller for relevant member offsets and function addresses for cve-2026-40369
CVE-2026-40369
CVE-2026-40369本地权限提升漏洞exp
Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges
Fetching description from NVD…
Fetching description from NVD…
POC pre-auth RCE on Exchange
Fetching description from NVD…
Combined PoC for CVE-2025-28434 and CVE-2025-59528
CVE-2025-58434 and CVE-2025-59528 chain POC
Exploitation Silentium HTB-CTF
Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)
Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password without prior …
The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This e…
FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a rep…
Fetching description from NVD…
Wordpress Plugin Planyo Online Reservation System <= 3.0 - Arbitrary File Read via SSRF
Fetching description from NVD…
Hands-on cybersecurity and CTF labs covering port reconnaissance, CMS stack discovery, VulnCMS, CVE-2026-58225, shell-to-root paths, Python, sudo, user switchi…
Fetching description from NVD…
Hands-on Learn SecByte CTF labs covering Venus reconnaissance, service discovery, cookies, PHP investigation, secrets, root-focused challenges, and CVE-2020-28…
Fetching description from NVD…
Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…
CVE-2026-8452 PreAuth RCE
Safely detect Citrix NetScaler CVE-2026-8452
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, e…
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
Fetching description from NVD…
RCE exploit for CVE-2023-3519
Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…
Citrix Scanner for CVE-2023-3519
CVE-2023-3519 vuln for nuclei scanner
Citrix ADC RCE CVE-2023-3519
Stack-Overflow on Citrix
Fetching description from NVD…
Three unauthenticated vulnerabilities in the Thinkware U3000 dashcam's local WiFi control protocol: arbitrary file write, arbitrary file read, and plaintext Wi…
Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app. PoC tooling behind CVE-2026-1010…
Fetching description from NVD…
CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH
Fetching description from NVD…
CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303
Fetching description from NVD…
Create PoC for CVE-2025-67303
Git CVE-2025-67303 payload
CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303
Fetching description from NVD…
Fetching description from NVD…
CVE-2026-50416: Windows 11 KASLR bypass
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.