A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
Show 2 repositories
Kestra Unauthenticated RCE Exploit (CVE-2026-53576)
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra - taken past the base PoC to show how a common Docker-so…
Fetching description from NVD…
Show 1 repositories
AD AutoPwn v4.13.0 — automated AD attack chain, zero-auth to Domain Admin. Discover/Kerberoast/AS-REP/AD CS ESC1-16/Shadow Creds/RBCD+KCD/Ghost-SPN/TGS-rewrite…
Fetching description from NVD…
Show 7 repositories
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerabilit…
Fix URL containing SPACES after Apache upgrade CVE-2023-25690
A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced XSS/RCE c…
HTTP Request Smuggling lab: Apache 2.4.55 CRLF injection
Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe's Contrabando…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product images, logos, and documents — by injecting their IDs into a review that is later trashed and purged. Exploitation requires a public review-form link (a 13-hex formId distributed to customers via e-mail), which exposes the nonce needed to reach the handler without any WordPress account or session.
Show 1 repositories
Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_local_forms_s…
Fetching description from NVD…
Show 1 repositories
Fetching description from NVD…
Show 1 repositories
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Show 1 repositories
A POC for CVE-2026-94129
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Show 1 repositories
POC for CVE-2026-94128
Fetching description from NVD…
Show 1 repositories
PoC for CVE-2026-72001 — Pangolin < 1.22.0 cross-organization resource authentication bypass via the share-link access-token endpoint (CWE-639, CVSS 8.1).
Fetching description from NVD…
Show 1 repositories
CVE-2026-79417 PoC
Fetching description from NVD…
Show 1 repositories
Path traversal vulnerability in Input-Leap
Fetching description from NVD…
Show 5 repositories
CVE-2026-8461
CVE-2026-8461 - Draft
A lab setup to test cve-2026-8461
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Show 2 repositories
CVE-2026-94127
Fetching description from NVD…
Show 1 repositories
This repository contains the exploit for CVE-2026-16764.
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from ancestor groups, and role assignment to a group lacks the required authorization check. Only deployments that delegate these management capabilities to accounts that are not full administrators are affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
Show 1 repositories
CVE-2026-94609: Writeup and POC
Fetching description from NVD…
Show 1 repositories
Unauthorized Bluetooth Classic pairing behavior consistent with CVE-2025-20701 on Skullcandy Dime 3 earbuds.
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the local network.
Show 1 repositories
CVE-2026-95675 · POC
Fetching description from NVD…
Show 8 of 11 repositories
FreePascal implementation of the UnrealIRCD CVE-2010-2075
Exploit for CVE:2010-2075. This exploit allows remote command execution in UnrealIRCd 3.2.8.1.
CVE-2010-2075 exploit
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
Script that exploits the vulnerability that allows establishing a backdoor in the UnrealIRCd service with CVE-2010-2075
CVE-2010-2075
Technical writeup and penetration testing report for CVE-2010-2075, demonstrating UnrealIRCd backdoor exploitation and remediation.
Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.
Fetching description from NVD…
Show 7 repositories
A Tool For CVE-2023-49070/CVE-2023-51467 Attack
Authentication Bypass Vulnerability Apache OFBiz < 18.12.10.
Exploit Of Pre-auth RCE in Apache Ofbiz!!
CVE-2023-49070 exploit and CVE-2023-49070 & CVE-2023-51467 vulnerability scanner
This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the user.
Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc
Fetching description from NVD…
Show 2 repositories
This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.
Show 1 repositories
Proof-of-Concept for CVE-2026-92680, the insecurely protected credentials vulnerability affecting Araxis Merge.
Fetching description from NVD…
Show 1 repositories
Proof-of-Concept (PoC) exploit for CVE-2019-7139, an unauthenticated SQL injection vulnerability in Magento (PRODSECBUG-2198). For educational and security res…
Fetching description from NVD…
Show 1 repositories
Fetching description from NVD…
Show 5 repositories
CVE-2018-9276 PRTG < 18.2.39 Authenticated Command Injection (Reverse Shell)
CVE-2018-9276 PRTG < 18.2.39 Reverse Shell (Python3 support)
Python Exploit for CVE: 2018-9276
CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.