Fetching description from NVD…
Show 1 repositories
CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write in tunnel_set_params (UDP 1701). Device fingerprint + optional OOB trigge…
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write in tunnel_set_params (UDP 1701). Device fingerprint + optional OOB trigge…
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97163 PoC: Joomla UP (lomart.fr) unauthenticated GitHub mini-install / remote action deployment (≤6.0.29). Detects plugin version, probes com_ajax ins…
CVE-2026-97163 PoC payload (UP plugin Joomla remote code installation)
Fetching description from NVD…
PoC for MLFlow unauth RCE
Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97161 PoC: Joomla UP (lomart.fr) unauthenticated path traversal / arbitrary file read via ajax-view (≤6.0.29). Fingerprints plugin, probes configurati…
Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
CVE-2026-97160 PoC for Joomla UP (lomart.fr): privileged {up php=} shortcode eval code injection in versions 5.0.0–5.2.0 and 6.0.0–6.0.29 (fix 5.2.1 / 6.1.0). …
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.
AcyMailing Enterprise for Joomla < 11.1.0: POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE when an …
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.
Unauthenticated SQL injection in Joomla YouTube Gallery (joomlaboat.com, com_youtubegallery) ≤ 5.7.2 — video search/sort on the public yg_api endpoint. Python …
Fetching description from NVD…
CVE-2026-64600
A C-based Linux security utility for detecting, safely verifying (Proof of Concept), and mitigating CVE-2026-64600 (RefluXFS). It provides kernel vulnerability…
A POC for the recently discovered Qualys bug on COW with XFS
A Linux kernel local privilege escalation affecting the XFS filesystem copy-on-write (CoW) path.
CVE-2026-64600 - Draft - Check todo
is an advanced security research framework designed to model, analyze, and demonstrate Local Privilege Escalation (LPE) mechanics associated with kernel-level …
Fetching description from NVD…
CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab
Fetching description from NVD…
PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare
CVE-2026-46331
CVE-2026-46331 and CVE-2026-43503
CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9
CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix
pedit COW
CVE-2026-46331 - Draft
cve-2026-46331-audit script
Fetching description from NVD…
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC
Fetching description from NVD…
PoC for CVE-2024-37054
NiteeshPujari/CVE-2024-37054, This repository contains a Proof of Concept (PoC) a critical deserialization vulnerability in MLflow that allows for Remote Code …
CVE-2024-37054 exploit and documentation
Generic PoC for MLflow pickle deserialization RCE (CVE-2024-37054-style). Poisons a registered model via the MLflow REST API to achieve code execution when the…
MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire
Fetching description from NVD…
CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC
An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debug…
CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using EC/Ed25519 …
CVE-2026-0073 – Android ADB Wireless Debugging Auth Bypass (CVSS 8.8) | Zero-click TLS type confusion to unauthenticated shell. 2 tools: Full Exploit (ADB shel…
A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled
CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.
CVE-2026-0073
Fetching description from NVD…
Path Traversal (Tar Slip) in fastcore via untar_dir()
Fetching description from NVD…
Security-hardened fork of OpenCode - Fixes CVE-2026-22812 (CVSS 8.8 RCE) that upstream refuses to patch
OpenCode < v1.0.216 - Unauthenticated RCE
CVE-2026-22812 - OpenCode Unauth RCE
Open security research on AI coding agent infrastructure. Agent-executable remediation manifests for CVE-2026-22812 and CVE-2026-22813.
CVE-2026-22812
Fetching description from NVD…
POC exploit for CVE-2024-49138
SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.
Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.
In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–491…
Fetching description from NVD…
Proof of concept & details for CVE-2025-21298
A Critical Windows OLE Zero-Click Vulnerability. This is a proof-of-concept for CVE-2025-21298 - Windows OLE Remote Code Execution Vulnerability (CVSS 9.8). Th…
Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.
LetsDefend SOC336 case study on CVE-2025-21298
SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough
LetsDefend SOC lab investigating CVE-2025-21298 Windows OLE Zero-Click RCE exploitation.
Fetching description from NVD…
CVE-2026-43682: HFS+ B-tree kernel heap overflow in macOS
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the attacker-controlled 'order_id' from the submitted form_data into a new booking session, which the 'bookly_render_complete' handler then trusts to look up and return the corresponding Order's secret token without verifying that the current session created that order. This makes it possible for unauthenticated attackers to enumerate sequential order IDs, disclose other customers' order tokens, retrieve calendar/appointment information via 'bookly_add_to_calendar' and permanently delete arbitrary non-completed bookings via 'bookly_rollback_order', which cascade-deletes the customer_appointment and (when no other customers are attached) the underlying appointment.
Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes appointm…
Bookly <= 28.2 Unauth IDOR + PII Leak + RCE Mass exploitation scanner for CVE-2026-93399 (CVSS 9.1 Critical) affecting the Bookly — Online Scheduling and Appo…
Fetching description from NVD…
Fetching description from NVD…
Malicious Register Directive Code Injection Exploit
CVE-2026-65660 - Draft or TODO
Fetching description from NVD…
WordPress Front End Users Plugin <= 3.2.32 is vulnerable to Arbitrary File Upload
WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)
Technical security research and PoC for CVE-2025-2005, an unauthenticated arbitrary file upload vulnerability affecting vulnerable versions of the WordPress Fr…
Fetching description from NVD…
Simple app to demonstrate CVE-2024-3651
Fetching description from NVD…
Wordpress Plainview Activity Monitor Plugin RCE (20161228)
cve-2018-15877
WP Plainview Activity Monitor auth RCE fix: broken manual cookie parse to stable Session handling. CVE-2018-15877 educational fix.
Fetching description from NVD…
C# and Impacket implementation of PrintNightmare CVE-2021-1675/CVE-2021-34527
Pure PowerShell implementation of CVE-2021-1675 Print Spooler Local Privilege Escalation (PrintNightmare)
Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527
Python implementation for PrintNightmare (CVE-2021-1675 / CVE-2021-34527)
CVE-2021-1675 Detection Info
PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。
CVE-2021-1675 (PrintNightmare)
PrintNightmare , Local Privilege Escalation of CVE-2021-1675 or CVE-2021-34527
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.