Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
khaleedbt/netis-cve-2026-36539

Скрипт проверки роутеров Netis

★ 0 · 2026-09-24
CVSS 8.6 HIGH CWE-434, CWE-862 Published 2026-09-24 PoCs 1 ★ 0 Last push 2026-09-24 (2 weeks, 2 days ago)

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uploading and executing a specially crafted script through the web management interface. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary operating system commands with root privileges resulting in complete compromise of the affected device.

Show 1 repositories
whoami-012/CVE-2026-96515
★ 0 · 2026-09-24
PoCs 1 ★ 1 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
nmlz/CVE-2026-62878
★ 1 · 2026-09-24
PoCs 1 ★ 0 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
BishopFox/CVE-2026-28326-check

Safely detect SolarWinds ARM RCE CVE-2026-28326

★ 0 · 2026-09-24
CVE-2025-24071
HOTMULTI PoC
PoCs 23 ★ 409 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 23 repositories
0x6rss/CVE-2025-24071_PoC

CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

★ 409 · 2025-03-20
ThemeHackers/CVE-2025-24071

Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)

★ 34 · 2025-03-27
FOLKS-iwd/CVE-2025-24071-msfvenom

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

★ 25 · 2025-03-18
Marcejr117/CVE-2025-24071_PoC

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

★ 24 · 2025-05-15
ex-cal1bur/SMB_CVE-2025-24071

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without …

★ 4 · 2025-06-11
LOOKY243/CVE-2025-24071-PoC

CVE-2025-24071 Proof Of Concept

★ 3 · 2025-05-27
TH-SecForge/CVE-2025-24071

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

★ 3 · 2025-06-09
ctabango/CVE-2025-24071_PoCExtra

Alternativa CVE-2025-24071_PoC

★ 2 · 2025-08-21
CVE-2024-42327
MULTI PoC
PoCs 11 ★ 48 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
BridgerAlderson/Zabbix-CVE-2024-42327-SQL-Injection-RCE

Zabbix CVE-2024-42327 PoC

★ 48 · 2025-01-03
aramosf/cve-2024-42327

cve-2024-42327 ZBX-25623

★ 38 · 2024-12-01
compr00t/CVE-2024-42327

PoC for CVE-2024-42327 / ZBX-25623

★ 18 · 2024-12-03
godylockz/CVE-2024-42327

Proof of concept for CVE-2024-42327: Zabbix privilege escalation to RCE

★ 9 · 2026-09-24
depers-rus/CVE-2024-42327
★ 3 · 2024-12-06
watchdog1337/CVE-2024-42327_Zabbix_SQLI

POC for CVE-2024-42327, an authenticated SQL Injection in Zabbix through the user.get API Method

★ 3 · 2024-12-08
874anthony/CVE-2024-42327_Zabbix_SQLi

This is for educational porpuses only. Please do not use agains unathorized systems.

★ 1 · 2025-04-19
RichJJ98/analise-vulnerabilidades-zabbix-notebooklm

Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque …

★ 1 · 2026-06-09
CVE-2023-40028
MULTI PoC
PoCs 10 ★ 13 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
0xyassine/CVE-2023-40028
★ 13 · 2024-03-23
0xDTC/Ghost-5.58-Arbitrary-File-Read-CVE-2023-40028

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that are symli…

★ 13 · 2025-01-07
monke443/CVE-2023-40028

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

★ 5 · 2024-12-21
rvzsec/CVE-2023-40028

CVE-2023-40028 PoC Exploit

★ 3 · 2024-12-28
godylockz/CVE-2023-40028

Proof of concept for CVE-2023-40028: Ghost arbitrary file read

★ 2 · 2026-09-24
Stp1t/CVE-2023-40028

Exploit for CVE-2023-40028 (for educational purposes)

★ 1 · 2026-01-29
sudlit/CVE-2023-40028
★ 0 · 2024-12-13
rehan6658/CVE-2023-40028
★ 0 · 2025-02-02
PoCs 4 ★ 6 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 4 repositories
D3Ext/CVE-2021-44967

POC exploit for CVE-2021-44967

★ 6 · 2025-08-11
godylockz/CVE-2021-44967

Proof of concept for CVE-2021-44967: LimeSurvey authenticated RCE

★ 1 · 2026-09-24
monke443/CVE-2021-44967

Authenticated (privileged) remote command execution in LimeSurvey Version 5.2.4 via upload and install plugins allows a remote user to upload arbitrary PHP cod…

★ 1 · 2025-04-18
kikechans/-Limesurvey-RCE-CVE-2021-44967

🔥 Automated RCE Exploit for Limesurvey (CVE-2021-44967). Cadena de explotación optimizada para escalada de privilegios. 🚀

★ 0 · 2026-05-23
PoCs 1 ★ 40 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
petermalone/CVE-2026-84543

Technical disclosure and PoC for CVE-2026-84543, a macOS SMB kernel vulnerability

★ 40 · 2026-09-24
CVE-2024-23692
MULTI PoC
PoCs 14 ★ 51 Last push 2026-09-24 (2 weeks, 2 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
verylazytech/CVE-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

★ 51 · 2025-03-24
jakabakos/CVE-2024-23692-RCE-in-Rejetto-HFS

Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)

★ 17 · 2024-06-13
0x20c/CVE-2024-23692-EXP

CVE-2024-23692 Exploit

★ 14 · 2024-06-18
vanboomqi/CVE-2024-23692
★ 12 · 2024-06-15
BBD-YZZ/CVE-2024-23692

CVE-2024-23692

★ 7 · 2024-06-18
NanoWraith/CVE-2024-23692
★ 4 · 2024-06-11
pradeepboo/Rejetto-HFS-2.x-RCE-CVE-2024-23692

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

★ 1 · 2024-07-10
NingXin2002/HFS2.3_poc

HFS2.3未经身份验证的远程代码执行(CVE-2024-23692)

★ 1 · 2024-12-21
PoCs 1 ★ 1 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
ustr/CVE-2026-25057

PoC for Zip Slip in MarkUs Assignment Configuration Uploads

★ 1 · 2026-09-23
PoCs 1 ★ 1 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
Wh02m1/CVE-2026-77812

DJI Drone Cleartext Bluetooth Transmission of Wi-Fi PSK and Session UUID — Proof of Concept for CVE-2026-77812.

★ 1 · 2026-09-23
PoCs 2 ★ 1 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
0xh7ml/CVE-2026-27626-PoC

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two independent…

★ 1 · 2026-07-03
abdelhakimgaferNetworkSec/Enigm-Writeup

Comprehensive penetration testing write-up and exploit details for Hack The Box - Enigma machine, covering local enumeration, OliveTin CVE-2026-27626 command i…

★ 1 · 2026-09-23
CVSS 6.8 MEDIUM CWE-79 Published 2026-09-23 PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute in an admin-facing meta box, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes in the session of a higher-privileged user who reviews the affected post.

Show 1 repositories
pervinzahidli/CVE-2026-88997

JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key

★ 0 · 2026-09-23
CVSS 8.6 HIGH CWE-78 Published 2026-09-23 PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system through a shell, causing arbitrary command execution in the victim's security context when they run the explore command against the untrusted package. This vulnerability was also addressed in version 5.20.0rc2 of the pre-release branch.

Show 1 repositories
SaiTeja-Erukude/CVE-2026-93349-frictionless-command-injection

Frictionless <= 5.20.0rc1 OS command injection via CLI explore.

★ 0 · 2026-09-23
PoCs 3 ★ 513 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 3 repositories
stong/CVE-2020-15368

CVE-2020-15368, aka "How to exploit a vulnerable driver"

★ 513 · 2022-04-14
R7flex/asrockploit

arbitrary code execution with CVE-2020-15368

★ 8 · 2024-10-12
egorrsp/CVE-2020-15368-AsrDrv103-research

Reverse engineering research of ASRock AsrDrv103.sys (CVE-2020-15368), covering its driver interface, encrypted request protocol, and privileged hardware acces…

★ 6 · 2026-09-23
CVE-2026-89274
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-09-19 PoCs 3 ★ 3 Last push 2026-09-23 (2 weeks, 3 days ago)

The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the `reviewBody` field, which is populated verbatim from the `comment_content` of approved `wprm-comment-rating` comments — without sanitizing or stripping shortcode tokens before execution; the subsequent `wp_strip_all_tags()` and `strip_shortcodes()` calls operate only on the output string after execution has already fully occurred, providing no protection against server-side shortcode invocation. This makes it possible for unauthenticated attackers to execute arbitrary registered WordPress shortcodes server-side on every recipe page render, causing shortcode output — such as attachment captions, private post fields, or other data exposed by installed shortcodes — to be embedded in the page's JSON-LD `reviewBody` metadata and disclosed to all visitors who load the recipe page. Successful exploitation requires the attacker's rated comment to pass the site's comment approval threshold, either via auto-approval or moderator action, before the injected shortcode begins executing on page loads.

Show 3 repositories
murrez/CVE-2026-89274

PoC for CVE-2026-89274: unauthenticated arbitrary shortcode execution in WP Recipe Maker ≤10.8.1 via recipe rating comments (JSON-LD). Python check/exploit/ver…

★ 3 · 2026-09-19
Polosss/By-Poloss..-.CVE-2026-89274

Unauthenticated Arbitrary Shortcode Execution

★ 0 · 2026-09-20
Hassham1/CVE-2026-89274-wp-recipe-maker-poc

CVE-2026-89274 — WP Recipe Maker <= 10.8.1 arbitrary shortcode execution via rating-comment reviewBody (CVSS 9.1): Docker validation lab with vulnerable (10.8.…

★ 0 · 2026-09-23
PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
Polosss/By-Poloss..-..CVE-2026-19125

Unauthenticated Authentication Bypass

★ 0 · 2026-09-23
PoCs 1 ★ 15 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
sylwia-budzynska/codeql-workshop

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

★ 15 · 2026-09-23
PoCs 3 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 3 repositories
HORKimhab/CVE-2026-86218

CVE-2026-86218 - Draft or TODO - N-central is vulnerable to a pre-auth remote code execution

★ 0 · 2026-09-17
Udyz/CVE-2026-86218

CVE-2026-86218 - N-able N-central Struts BeanUtils Unauthenticated RCE

★ 0 · 2026-09-14
super-meuw/CVE-2026-86218

CVE-2026-86218

★ 0 · 2026-09-23
CVE-2021-40444
HOTMULTI PoC
PoCs 34 ★ 1835 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 34 repositories
lockedbyte/CVE-2021-40444

CVE-2021-40444 PoC

★ 1835 · 2021-12-25
klezVirus/CVE-2021-40444

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

★ 836 · 2023-10-11
aslitsecurity/CVE-2021-40444_builders

This repo contain builders of cab file, html file, and docx file for CVE-2021-40444 exploit

★ 174 · 2021-10-11
Edubr2020/CVE-2021-40444--CABless

Modified code so that we don´t need to rely on CAB archives

★ 105 · 2021-09-22
k8gege/CVE-2021-40444
★ 21 · 2021-09-14
ozergoker/CVE-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444

★ 18 · 2021-09-29
rfcxv/CVE-2021-40444-POC
★ 18 · 2021-09-09
PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
Nefhara/CVE-2020-6857

PoC CVE-2020-6857

★ 0 · 2026-09-23
CVE-2025-64512
MULTI PoC
PoCs 10 ★ 8 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
luigigubello/CVE-2025-64512-Polyglot-PoC

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

★ 8 · 2026-04-10
matesz44/CVE-2025-64512

CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads

★ 4 · 2026-07-19
BardLaudian/CVE-2025-64512

CLI wrapper around the official PoC for CVE-2025-64512 — pdfminer.six insecure pickle deserialization via crafted PDF (RCE)

★ 1 · 2026-09-23
joeack123/PoC-for-CVE-2025-64512

PoC script for CVE-2025-64512

★ 0 · 2026-07-19
MehdiChyhab/CVE-2025-64512-exploit

CVE-2025-64512 - pdfminer.six Remote Code Execution Exploit

★ 0 · 2026-07-21
stoic-crawler/CVE-2025-64512

Exploit for CVE-2025-64512 to get a reverse shell.

★ 0 · 2026-07-22
DodgeNefoli/CVE-2025-64512
★ 0 · 2026-08-12
PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
Leox48/CVE-2026-1769-WriteUp

Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)

★ 0 · 2026-09-23
CVE-2025-22457
MULTI PoC
PoCs 6 ★ 73 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 6 repositories
sfewer-r7/CVE-2025-22457

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and …

★ 73 · 2025-04-25
securekomodo/CVE-2025-22457

CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE

★ 18 · 2025-04-17
Vinylrider/ivantiunlocker

Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN

★ 2 · 2025-04-13
TRone-ux/CVE-2025-22457

PoC CVE-2025-22457

★ 1 · 2025-05-25
benmevic/cve-2025-22457

Altay takımı haftalık sunumu için yaptığım cve-2025-22457 zafiyeti demo uygulaması

★ 0 · 2026-07-10
< Prev Page 25 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.