Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
351PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 1 repositories
lorenzog/CVE-2020-13664

PoC for CVE-2020-13664

★ 0 · 2026-09-28
PoCs 2 ★ 0 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
murrez/CVE-2026-18143

Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_uploaded_fil…

★ 0 · 2026-09-26
Wayang1337/CVE-2026-18143

Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup

★ 0 · 2026-09-28
CVE-2026-38526
MULTI PoC
PoCs 13 ★ 7 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
NathanHimself/CVE-2026-38526-PoC

CVE-2026-38526 | Krayin CRM v2.2.x Authenticated RCE - Unrestricted PHP File Upload via TinyMCE

★ 7 · 2026-05-16
CerberusMrXi/KrayinCRM-RCE-Exploit-CVE-2026-38526

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads, auto shell ge…

★ 3 · 2026-07-14
pawpic/CVE-2026-38526-POC

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

★ 1 · 2026-06-26
Shirouuu/Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git objects. Edu…

★ 1 · 2026-09-14
mmoobbeeiidat-design/Hack-The-Box-Nexus-Findings-Report

HTB_Nexus Penetration Test Report – Comprehensive security assessment documenting credential leakage from Gitea, CVE-2026-38526 exploitation in Krayin CRM, and…

★ 0 · 2026-07-06
diamorphine666/CVE-2026-38526-Exploit

Exploit for Authenticated Remote Code Execution (RCE) in Krayin CRM v2.2.x (CVE-2026-38526)

★ 0 · 2026-07-06
b0nyo/PoC-CVE-2026-38526

Automated exploit for Krayin CRM ≤ 2.2.x.

★ 0 · 2026-07-09
Resolvdd/CVE-2026-38526-PoC-htb-nexus

A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x

★ 0 · 2026-07-19
PoCs 2 ★ 30 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
Malwation/CVE-2026-43786

Proof of concept for CVE-2026-43786, a local privilege escalation vulnerability in macOS CoreServices that allows an application to gain root privileges.

★ 30 · 2026-09-21
0xBlackash/CVE-2026-43786

CVE-2026-43786

★ 2 · 2026-09-28
PoCs 2 ★ 2 Last push 2026-09-28 (1 week, 4 days ago)

Fetching description from NVD…

Show 2 repositories
0xBlackash/CVE-2026-6471

CVE-2026-6471

★ 2 · 2026-09-28
goldendivider/cve-2026-6471-postgres-logical-decoding-dlopen

postgres CVE-2026-6471 Exploit

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
do4choo/CVE-2026-5054

CVE-2026-5054

★ 0 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
do4choo/CVE-2026-5053

CVE-2026-5053

★ 0 · 2026-09-28
CVE-2026-41651
HOTMULTI PoC
PoCs 12 ★ 125 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 8 of 12 repositories
Vozec/CVE-2026-41651
★ 125 · 2026-04-23
ZeroDayEvil/CVE-2026-41651
★ 24 · 2026-09-28
baph00met/CVE-2026-41651

CVE-2026-41651 — PackageKit TOCTOU LPE

★ 17 · 2026-04-25
0xBlackash/CVE-2026-41651

CVE-2026-41651

★ 13 · 2026-04-25
shibaaa204/Pack2TheRoot

Poc for Pack2TheRoot CVE-2026-41651

★ 9 · 2026-04-29
CipherCloak/CVE-2026-41651
★ 8 · 2026-04-24
dinosn/pack2theroot-lab

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

★ 8 · 2026-04-25
Lutfifakee-Project/CVE-2026-41651

Exploit for CVE-2026-41651 - PackageKit TOCTOU Local Privilege Escalation (Pack2TheRoot)

★ 5 · 2026-05-20
CVE-2026-75604
HOTMULTI PoC
PoCs 5 ★ 105 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 5 repositories
rafabd1/CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

★ 105 · 2026-08-28
ZeroDayEvil/CVE-2026-75604-PoC
★ 26 · 2026-09-28
e4zyy/Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilitie…

★ 3 · 2026-08-27
HackSpeak/CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

★ 2 · 2026-08-26
FORTBRIDGE-UK/cve-2026-75604

Research lab and exploit chain for CVE-2026-75604: path traversal in the Next.js incremental cache, to RCE on Windows.

★ 0 · 2026-09-05
PoCs 3 ★ 129 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 3 repositories
oxfemale/CVE-2026-20817

Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.

★ 129 · 2026-02-19
ZeroDayEvil/CVE-2026-20817
★ 24 · 2026-09-28
dwgth4i/CVE-2026-20817

PoC for CVE-2026-20817

★ 0 · 2026-05-28
CVE-2026-40369
HOTMULTI PoC
PoCs 7 ★ 261 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 7 repositories
orinimron123/CVE-2026-40369-EXPLOIT

Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandb…

★ 261 · 2026-05-18
ZeroDayEvil/CVE-2026-40369-EXPLOIT
★ 24 · 2026-09-28
piffd0s/ntoskrnl-metadata

eprocess offset puller for relevant member offsets and function addresses for cve-2026-40369

★ 4 · 2026-05-22
0xBlackash/CVE-2026-40369

CVE-2026-40369

★ 1 · 2026-06-18
ercihan/CVE-2026-40369
★ 0 · 2026-05-22
CCELEND/CVE-2026-40369

CVE-2026-40369本地权限提升漏洞exp

★ 0 · 2026-06-23
dbgbgtf1/cve-2026-40369-exploit

Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges

★ 0 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 2 ★ 185 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
hypnguyen1209/CVE-2026-62911

POC pre-auth RCE on Exchange

★ 185 · 2026-08-22
ZeroDayEvil/CVE-2026-62911
★ 23 · 2026-09-28
CVE-2025-58434
MULTI PoC
PoCs 16 ★ 18 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 8 of 16 repositories
kartik2005221/CVE-2025-58434-AND-59528-POC

Combined PoC for CVE-2025-28434 and CVE-2025-59528

★ 18 · 2026-04-13
AzureADTrent/CVE-2025-58434-59528

CVE-2025-58434 and CVE-2025-59528 chain POC

★ 5 · 2026-04-12
jwsly12/CVE-2025-58434-59528-htb-ctf

Exploitation Silentium HTB-CTF

★ 2 · 2026-04-28
CVETeam/FlowiseAI-Critical-KillChain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

★ 1 · 2026-04-14
kartik2005221/CVE-2025-58434-poc
★ 1 · 2026-04-12
arensballiu/Flowise-CVE-2025-58434-PasswordReset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password without prior …

★ 1 · 2026-09-28
SteamPunk424/CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or verification. This e…

★ 1 · 2026-04-20
0xDaeras/Flowise-CVE-2025-58434-Chain-59528

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE. Includes a rep…

★ 1 · 2026-05-08
PoCs 1 ★ 2 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
anirbala98/CVE-2026-3576

Wordpress Plugin Planyo Online Reservation System <= 3.0 - Arbitrary File Read via SSRF

★ 2 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-CMS-CVE-Shell-to-Root-Privilege-Escalation-CTF-Labs

Hands-on cybersecurity and CTF labs covering port reconnaissance, CMS stack discovery, VulnCMS, CVE-2026-58225, shell-to-root paths, Python, sudo, user switchi…

★ 0 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
sifatnotes/Learn-SecByte-Venus-Rips-Recon-PHP-CVE-CTF-Labs

Hands-on Learn SecByte CTF labs covering Venus reconnaissance, service discovery, cookies, PHP investigation, secrets, root-focused challenges, and CVE-2020-28…

★ 0 · 2026-09-28
CVE-2026-8452
MULTI PoC
PoCs 5 ★ 96 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 5 repositories
securekomodo/citrixInspector

Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…

★ 96 · 2026-09-28
watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452

CVE-2026-8452 PreAuth RCE

★ 65 · 2026-08-14
BishopFox/CVE-2026-8452-check

Safely detect Citrix NetScaler CVE-2026-8452

★ 1 · 2026-08-20
maxprog-svg/CitrixBleedCVE-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, e…

★ 0 · 2026-08-30
techupdate24/citrix-netscaler-cve-2026-8452-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-27
CVE-2023-3519
HOTMULTI PoC
PoCs 13 ★ 228 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 8 of 13 repositories
BishopFox/CVE-2023-3519

RCE exploit for CVE-2023-3519

★ 228 · 2023-08-23
securekomodo/citrixInspector

Passively fingerprint Citrix ADC / NetScaler ADC & Gateway builds and detect known CVEs — CVE-2023-3519, CitrixBleed 2/3, CVE-2026-8452, and CVE-2026-88771/887…

★ 96 · 2026-09-28
telekom-security/cve-2023-3519-citrix-scanner

Citrix Scanner for CVE-2023-3519

★ 54 · 2023-07-24
mr-r3b00t/CVE-2023-3519
★ 13 · 2023-07-21
SalehLardhi/CVE-2023-3519

CVE-2023-3519 vuln for nuclei scanner

★ 11 · 2023-07-21
Chocapikk/CVE-2023-3519

Citrix ADC RCE CVE-2023-3519

★ 5 · 2026-01-08
dhammerg/CVE-2023-3519

Stack-Overflow on Citrix

★ 5 · 2024-10-06
PoCs 2 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
turretsec/disclosure-thinkware-u3000

Three unauthenticated vulnerabilities in the Thinkware U3000 dashcam's local WiFi control protocol: arbitrary file write, arbitrary file read, and plaintext Wi…

★ 0 · 2026-09-28
turretsec/u3000py

Python client for the Thinkware U3000 dashcam's local WiFi control protocol, reverse-engineered from the official Android app. PoC tooling behind CVE-2026-1010…

★ 0 · 2026-09-28
PoCs 2 ★ 142 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
G4sp4rCS/CVE-2026-42980-POC

CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH

★ 142 · 2026-07-07
ZeroDayEvil/CVE-2026-42980-PoC
★ 35 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
Si13NTTT/CVE-2026-22777

CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303

★ 0 · 2026-09-28
CVE-2025-67303
MULTI PoC
PoCs 6 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 6 repositories
joker-xiaoyan/CVE-2025-67303

test

★ 0 · 2026-01-09
maybe-O/CVE-2025-67303
★ 0 · 2026-01-21
ExploreUnknowed/CVE-2025-67303
★ 0 · 2026-01-22
materaj2/exploit_cve_2025_67303

Create PoC for CVE-2025-67303

★ 0 · 2026-01-24
jcaz2378/ComfyUIrce

Git CVE-2025-67303 payload

★ 0 · 2026-05-13
Si13NTTT/CVE-2026-22777

CVE-2026-22777 ComfyUI-Manager CRLF Injection leading to RCE chained with CVE-2025-67303

★ 0 · 2026-09-28
PoCs 1 ★ 2 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
jvidhan/cve-2026-28912
★ 2 · 2026-09-28
PoCs 2 ★ 47 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
karollooool/CVE-2026-50416-writeup-and-poc

CVE-2026-50416: Windows 11 KASLR bypass

★ 47 · 2026-08-17
< Prev Page 21 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.