Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
350PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 2 ★ 8 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
aavamin/CVE-2026-24423

CVE-2026-24423 exp

★ 8 · 2026-01-29
CyberAlp0/SmarterMail-CVE-2026-24423

Unauthenticated RCE PoC for CVE-2026-24423 in SmarterTools SmarterMail (ConnectToHub). For authorized security testing, CTFs, and research only.

★ 0 · 2026-09-28
PoCs 1 ★ 3 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
yairHinkis/CVE-2026-56096

Proof of Concept and Write-up for CVE-2026-56096 (Blind Parameter Injection in TYPO3 EXT:solr)

★ 3 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-100721

CVE-2026-100721 PoC: vm2 <3.12.2 NodeVM external allowlist bypass → sandbox escape / host RCE. Local Node lab (evil-left-pad), remote sandbox API mass exploit,…

★ 0 · 2026-09-28
PoCs 1 ★ 1 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-82384

CVE-2026-82384 PoC: Apache Roller 6.1.5 unauthenticated XML-RPC ex:serializable Java deserialization (pre-auth RCE). Check, ysoserial exploit, mass bulk scanni…

★ 1 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
4ybrick/CVE-2026-100903

GEOritm CVE

★ 0 · 2026-09-28
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
heapframe/seetong-ts81xxd3x-rce

CVE-2026-100886 | Unauthenticated Remote Code Execution toolkit.

★ 0 · 2026-09-28
CVSS 8.5 HIGH CWE-77, CWE-78 Published 2026-09-20 PoCs 2 ★ 4 Last push 2026-09-28 (1 week, 5 days ago)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

Show 2 repositories
HackSpeak/CVE-2026-93958

D-Link R95 (BE9500) DHMAPI SetTimeSettings command injection -> root RCE PoC (CVE-2026-93958); for authorized testing

★ 4 · 2026-09-20
murrez/CVE-2026-93958

CVE-2026-93958 PoC: D-Link R95 BE9500 DHMAPI SetTimeSettings NTPServer authenticated root command injection. DHMAPI login, RCE verify, mass bulk exploit mode, …

★ 0 · 2026-09-28
CVE-2025-49132
MULTI PoC
PoCs 27 ★ 25 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 8 of 27 repositories
YoyoChaud/CVE-2025-49132

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

★ 25 · 2026-02-09
Zen-kun04/CVE-2025-49132

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

★ 17 · 2025-06-22
malw0re/CVE-2025-49132-Mods
★ 12 · 2026-02-14
63square/CVE-2025-49132

PoCs for CVE-2025-49132

★ 5 · 2025-06-24
qiaojojo/CVE-2025-49132_poc

Pterodactyl翼龙面板CVE-2025-49132批量检测☝️🤓

★ 4 · 2025-06-23
str1keboo/CVE-2025-49132

This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

★ 4 · 2026-02-08
popyue/CVE-2025-49132

CVE For Pterodactyl (For Study and Education)

★ 4 · 2026-02-16
0xtensho/CVE-2025-49132-poc
★ 3 · 2026-03-13
PoCs 1 ★ 0 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-85984

CVE-2026-85984 PoC: WordPress miniOrange OTP ≤5.5.5 unauth admin bypass (mo_wp_login_intent=otp + empty password). Check/exploit, user enum, colored CLI. https…

★ 0 · 2026-09-28
PoCs 2 ★ 4 Last push 2026-09-28 (1 week, 5 days ago)

Fetching description from NVD…

Show 2 repositories
DeadExpl0it/CVE-2026-78006-POC

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

★ 4 · 2026-09-12
antid00t/CVE-2026-78006-CVE-2026-78159

The Events Calendar Wordpress Plugin Mass Exploit CVE-2026-78006 & CVE-2026-78159

★ 3 · 2026-09-28
CVSS 7.0 HIGH CWE-444, CWE-863 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 5 days ago)

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.

Show 1 repositories
Boreas37/CVE-2026-88008-PoC

CVE-2026-88008 - Traefik (<=2.11.56 / <=3.7.12): a client-controlled h2c upgrade tunnels past routers and middleware (BasicAuth/ForwardAuth/IPAllowList), unaut…

★ 0 · 2026-09-27
PoCs 3 ★ 0 Last push 2026-09-27 (1 week, 5 days ago)

Fetching description from NVD…

Show 3 repositories
tom025/ply_exploit_rejection

Arguments to reject CVE-2025-56005

★ 0 · 2026-01-27
gdfurr98/ply-safepickle

This is a modified version of PLY 3.11, from PyPI (current defunct git repo is not current to PyPI) which reimplements the pickle function in yacc.py to resolv…

★ 0 · 2026-09-27
gdfurr98/ply-cve-2025-56005-lab

Lab demonstrating that CVE-2025-56005 is real and does allow arbitrary code execution at a minimum (the debate about RCE notwithstanding here), and shows that …

★ 0 · 2026-09-27
PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 5 days ago)

Fetching description from NVD…

Show 1 repositories
Boreas37/CVE-2026-71963-PoC

CVE-2026-71963 - Hermes Agent 0.18.2-0.21.0 RCE via a repository-delivered .git/config (core.fsmonitor). Stdlib-only Python, verified on real 0.21.0 with a cle…

★ 0 · 2026-09-27
PoCs 3 ★ 4 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 3 repositories
murrez/CVE-2026-14281

Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → admin. Pyt…

★ 4 · 2026-09-25
langz337/CVE-2026-14281

CVE-2026-14281

★ 1 · 2026-09-26
abatsakidis/CVE-2026-14281-check

A Windows-friendly, non-destructive Python checker for detecting WordPress installations potentially affected by CVE-2026-14281.

★ 0 · 2026-09-27
PoCs 2 ★ 13 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 2 repositories
predyy/CVE-2026-28695

CVE-2026-28695 PoC - Authenticated blind remote code execution in Craft CMS.

★ 13 · 2026-09-27
gbuyssens/CVE-2026-28695-craft-rce-bypass

Authenticated, **blind** remote code execution in Craft CMS. Fix for CVE-2026-28695

★ 1 · 2026-09-27
PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
H4zaz/CVE-2026-76547

PHP Object Injection in Profile Builder < 4.0.1

★ 0 · 2026-09-27
PoCs 1 ★ 4 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
nth347/mediawiki-CVE-2026-100382
★ 4 · 2026-09-27
PoCs 1 ★ 1 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
FORTBRIDGE-UK/libheif-grid-nextjs-rce

Private Fortbridge PoC for the CVE-2026-32740 Next.js/sharp leak-to-memcpy-GOT RCE chain

★ 1 · 2026-09-27
PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-100835

CVE-2026-100835 PoC: Edgeless Contrast <1.16.0 remote attestation relay (aTLS / CWE-295). Manifest audit (AllowedChipIDs/AllowedPIIDs), version & coordinator p…

★ 0 · 2026-09-27
PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
h3ck13r/CVE-2021-28235

CVE-2021-28235 PoC

★ 0 · 2026-09-27
PoCs 1 ★ 1 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
h3ck13r/CVE-2026-35204

CVE-2026-35204 PoC

★ 1 · 2026-09-27
PoCs 2 ★ 6 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 2 repositories
khoatran107/cve-2025-39682

A variant of CVE-2024-58239

★ 6 · 2025-10-14
suominen/CVE-2025-39682

Tracking CVE-2025-39682, the Linux kernel kTLS zero-length record use-after-free

★ 0 · 2026-09-27
PoCs 2 ★ 3 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 2 repositories
n1k0oowang/CVE-2025-39964_EXP

CVE-2025-39964 EXP

★ 3 · 2025-11-13
suominen/CVE-2025-39964

Tracking CVE-2025-39964, the Linux kernel AF_ALG concurrent-write race

★ 0 · 2026-09-27
PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 6 days ago)

Fetching description from NVD…

Show 1 repositories
suominen/CVE-2026-53266

Tracking CVE-2026-53266, the Linux kernel ebtables SNAT ARP-rewrite page-cache write

★ 0 · 2026-09-27
CVSS 6.9 MEDIUM CWE-918 Published 2026-09-01 PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 6 days ago)

Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to override the server-configured backend and redirect connections to attacker-chosen hosts.

Show 1 repositories
rahulreddykarne/CVE-2026-8712-Wyoming

CVE-2026-8712: Unauthenticated SSRF / Backend URI Override in Wyoming HTTP API via uri Query Parameter

★ 0 · 2026-09-27
< Prev Page 22 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.