Fetching description from NVD…
Show 2 repositories
PoC for CVE-2022-3218
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
PoC for CVE-2022-3218
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image). transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.
CVE-2026-90898 - Draft or TODO
Fetching description from NVD…
CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection
CVE-2026-5118-exp_wordpress_Divi Form Builder
CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce…
Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider creates an additional 'sibling' router that matches on the host alone, carries only the RedirectRegex middleware, and still points at the parent router's protected backend service. Because RedirectRegex is not a terminal handler, a request its pattern does not match is forwarded to the backend, and because the redirect pattern only accepts a numeric port while Traefik's host matcher canonicalizes the authority via net.SplitHostPort, a request with a non-numeric or empty port (for example 'Host: www.example.com:x') selects the sibling router, misses the redirect, and is proxied to the protected backend with none of the Ingress's annotation-derived middlewares applied. This discards not only authentication (e.g. BasicAuth) but every annotation-derived middleware, including source-IP allowlisting. Traefik v2 and v3 releases before v3.7.0 are not affected. The issue is fixed in v3.7.12.
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin/js/common.js when a contextual help tab anchor is clicked.
Fetching description from NVD…
Fetching description from NVD…
A method for CVE-2025-31710 and to connect to cmd_skt to obtain a root shell on unisoc unpatched models
Fetching description from NVD…
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-23921
Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque …
Fetching description from NVD…
container escape POCs for CVE-2026-80521 and CVE-2026-52910
container escape POCs for CVE-2026-80521 and CVE-2026-52910
Fetching description from NVD…
# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.
Fetching description from NVD…
CVE-2026-48519 pre-auth rce poc in IBM langflow <= 1.9.1
Fetching description from NVD…
Improper Restriction of Rendered UI Layers or Frames (CWE-1021)
Fetching description from NVD…
CVE-2023-6931 kernel panic PoC
Fetching description from NVD…
This project describes detailed information about the CVE-2026-51772 vulnerability.
Fetching description from NVD…
CVE-2026-68376 - Ubuntu Kernel 7.0.0-30
Fetching description from NVD…
WordPress Give Tributes CVE-2026-19658: Python 3 checker, FOFA helper, legacy Give form exploit path (CWE-502, CVSS 9.8).
Fetching description from NVD…
PoC for NVIDIAScape bug
CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit
cve-2025-23266-migration-bypass
CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains…
Original offensive security research into Linux container boundary weaknesses. Whitepaper 1: OCI hook isolation failures in the NVIDIA Container Toolkit (CVE-2…
Fetching description from NVD…
CVE-2026-13355 PoC — Meta Box AIO ≤3.11.0 unauthenticated admin privesc via MB Frontend Submission + User Profile shortcode chain. Python check/exploit, FOFA h…
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
HPLIP < 3.26.6 — Full admin takeover via PAPPL web interface (no auth). Related to CVE-2026-91097 through CVE-2026-91106 (CVSS 9.3)
Mass check/research exploit for HP HPLIP CVE-2026-91097–91106 (<3.26.6), PAPPL :8000 IPP probes + hpssd templates
Fetching description from NVD…
SQL injection vulnerability in Android 17 (AOSP)
CVE-2026-28576 (GHSA-ph86-9mcx-3p6r) — Android Contacts Provider SQL Injection via targetSdk-gated ENFORCE_STRICT_SQL_CHECKS. Zero-permission boolean-oracle Po…
Fetching description from NVD…
Proof of concept exploit code for CVE-2026-0769
Fetching description from NVD…
Proof of concept exploit code for CVE-2026-93680
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
POC-CVE-2026-93674 Authenticated Blind command injection proof of concept exploit code
Fetching description from NVD…
WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This vulnerabil…
Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit
The official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol.
Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)
Exploit of the CVE-2025-36911 vulnerability in Python for testing our own equipment
WhisperPair (CVE-2025-36911) POC for ESP32 device
A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability
This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.
Fetching description from NVD…
CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.
Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).
Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"
Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM proba…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.