Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 2 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
MoisesTapia/cve-2022-3218
★ 0 · 2025-12-18
mermehr/MouseServer-1.7.8.5-RCE

PoC for CVE-2022-3218

★ 0 · 2026-09-23
CVE-2026-90898
CRITICAL
CVSS 9.8 CRITICAL CWE-284, CWE-306 Published 2026-09-14 PoCs 1 ★ 0 Last push 2026-09-23 (2 weeks, 3 days ago)

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is enough to run a program as the Bifrost process user (appuser on the official image).  transports/v2.1.0 refuses an unauthenticated stdio registration with 403. transports/v2.0.0 still allows it.

Show 1 repositories
HORKimhab/CVE-2026-90898

CVE-2026-90898 - Draft or TODO

★ 0 · 2026-09-23
CVE-2026-5118
MULTI PoC
PoCs 6 ★ 5 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 6 repositories
zycoder0day/CVE-2026-5118

CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection

★ 5 · 2026-05-21
puj790201-lab/CVE-2026-5118

CVE-2026-5118-exp_wordpress_Divi Form Builder

★ 1 · 2026-05-21
Jenderal92/CVE-2026-5118

CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce…

★ 0 · 2026-05-30
Yucaerin/CVE-2026-5118

Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection

★ 0 · 2026-05-22
1beelze/CVE-2026-5118
★ 0 · 2026-07-13
SangSenimanWartefak/CVE-2026-5118
★ 0 · 2026-09-22
CVE-2026-88877
CRITICAL
CVSS 9.3 CRITICAL CWE-639 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider creates an additional 'sibling' router that matches on the host alone, carries only the RedirectRegex middleware, and still points at the parent router's protected backend service. Because RedirectRegex is not a terminal handler, a request its pattern does not match is forwarded to the backend, and because the redirect pattern only accepts a numeric port while Traefik's host matcher canonicalizes the authority via net.SplitHostPort, a request with a non-numeric or empty port (for example 'Host: www.example.com:x') selects the sibling router, misses the redirect, and is proxied to the protected backend with none of the Ingress's annotation-derived middlewares applied. This discards not only authentication (e.g. BasicAuth) but every annotation-derived middleware, including source-IP allowlisting. Traefik v2 and v3 releases before v3.7.0 are not affected. The issue is fixed in v3.7.12.

Show 1 repositories
CVSS 7.2 HIGH CWE-79 Published 2026-09-18 PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin/js/common.js when a contextual help tab anchor is clicked.

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 137 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
Skorpion96/unisoc-su

A method for CVE-2025-31710 and to connect to cmd_skt to obtain a root shell on unisoc unpatched models

★ 137 · 2026-09-22
PoCs 2 ★ 4 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 2 repositories
qucklecrabik/CVE-2026-23921

This repository contains a proof-of-concept (PoC) exploit for CVE-2026-23921

★ 4 · 2026-09-22
RichJJ98/analise-vulnerabilidades-zabbix-notebooklm

Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia de ataque …

★ 1 · 2026-06-09
PoCs 2 ★ 47 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 2 repositories
Markakd/Container_escape

container escape POCs for CVE-2026-80521 and CVE-2026-52910

★ 47 · 2026-09-22
rifkyards/Container_escape-CVE-2026-80521-CVE-2026-52910

container escape POCs for CVE-2026-80521 and CVE-2026-52910

★ 0 · 2026-09-22
PoCs 1 ★ 6 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
Robertmak2014-sudow/CVE-2026-28995

# CVE-2026-28995 Proof of Concept for CVE-2026-28995 — Path Traversal vulnerability in App Intents on iOS 26.4.2 and below.

★ 6 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
lukehebe/IBM-Langflow-CVE-2026-48519-poc

CVE-2026-48519 pre-auth rce poc in IBM langflow <= 1.9.1

★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
ShadowForge-Cyber/CVE-2026-84388-POC

Improper Restriction of Rendered UI Layers or Frames (CWE-1021)

★ 0 · 2026-09-22
PoCs 2 ★ 2 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 2 repositories
K0n9-log/CVE-2023-6931

CVE-2023-6931 kernel panic PoC

★ 2 · 2025-01-06
Yutori-Natsu/cve-2023-6931-pipa
★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
sadandbset/CVE-2026-51772-CVE-2026-51773

This project describes detailed information about the CVE-2026-51772 vulnerability.

★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
gagaltotal/CVE-2026-68376-Ubuntu-7.0.0-30-Poc

CVE-2026-68376 - Ubuntu Kernel 7.0.0-30

★ 0 · 2026-09-22
PoCs 1 ★ 1 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-19658

WordPress Give Tributes CVE-2026-19658: Python 3 checker, FOFA helper, legacy Give form exploit path (CWE-502, CVSS 9.8).

★ 1 · 2026-09-22
CVE-2025-23266
MULTI PoC
PoCs 5 ★ 15 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 5 repositories
jpts/cve-2025-23266-poc

PoC for NVIDIAScape bug

★ 15 · 2025-07-19
r0binak/CVE-2025-23266

CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit

★ 1 · 2026-03-19
Mindasy/cve-2025-23266-migration-bypass

cve-2025-23266-migration-bypass

★ 1 · 2025-09-04
mrk336/CVE-2025-23266

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The article explains…

★ 1 · 2025-09-07
CR1MS0N-Operator/security-research

Original offensive security research into Linux container boundary weaknesses. Whitepaper 1: OCI hook isolation failures in the NVIDIA Container Toolkit (CVE-2…

★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-13355

CVE-2026-13355 PoC — Meta Box AIO ≤3.11.0 unauthenticated admin privesc via MB Frontend Submission + User Profile shortcode chain. Python check/exploit, FOFA h…

★ 0 · 2026-09-22
CVSS 7.0 HIGH CWE-787 Published 2026-09-16 PoCs 2 ★ 1 Last push 2026-09-22 (2 weeks, 4 days ago)

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Show 2 repositories
Nxploited/CVE-2026-91097-CVE-2026-91106

HPLIP < 3.26.6 — Full admin takeover via PAPPL web interface (no auth). Related to CVE-2026-91097 through CVE-2026-91106 (CVSS 9.3)

★ 1 · 2026-09-22
murrez/HP-HPLIP-Mass-CVE-checker-2026-09-

Mass check/research exploit for HP HPLIP CVE-2026-91097–91106 (<3.26.6), PAPPL :8000 IPP probes + hpssd templates

★ 0 · 2026-09-21
PoCs 2 ★ 43 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 2 repositories
mobilehackinglab/CVE-2026-28576-poc

SQL injection vulnerability in Android 17 (AOSP)

★ 43 · 2026-09-07
Aayushbankar/cve-2026-28576

CVE-2026-28576 (GHSA-ph86-9mcx-3p6r) — Android Contacts Provider SQL Injection via targetSdk-gated ENFORCE_STRICT_SQL_CHECKS. Zero-permission boolean-oracle Po…

★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
rmhowe425/POC-CVE-2026-0769

Proof of concept exploit code for CVE-2026-0769

★ 0 · 2026-09-22
PoCs 1 ★ 0 Last push 2026-09-22 (2 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
rmhowe425/POC-CVE-2026-93680

Proof of concept exploit code for CVE-2026-93680

★ 0 · 2026-09-22
CVE-2026-93674
CRITICAL
CVSS 9.8 CRITICAL CWE-94 Published 2026-10-07 PoCs 1 ★ 4 Last push 2026-09-22 (2 weeks, 4 days ago)

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Show 1 repositories
rmhowe425/POC-CVE-2026-93674

POC-CVE-2026-93674 Authenticated Blind command injection proof of concept exploit code

★ 4 · 2026-09-22
CVE-2025-36911
HOTMULTI PoC
PoCs 10 ★ 857 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
zalexdev/wpair-app

WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This vulnerabil…

★ 857 · 2026-01-18
SpectrixDev/DIY_WhisperPair

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

★ 107 · 2026-05-28
KULeuven-COSIC/WhisperPair

The official reference implementation & vulnerability verification of our attack WhisperPair (CVE-2025-36911) which affects Google's Fast Pair protocol.

★ 105 · 2026-09-21
Ymsniper/Whisper_Bully

Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)

★ 39 · 2026-07-13
PentHertz/CVE-2025-36911-exploit

Exploit of the CVE-2025-36911 vulnerability in Python for testing our own equipment

★ 27 · 2026-01-28
PivotChip/FrostedFastPair

WhisperPair (CVE-2025-36911) POC for ESP32 device

★ 15 · 2026-01-31
aalex954/whisperpair-poc-tool

A security research tool that identifies and demonstrates the CVE-2025-36911: Fast Pair Pairing Mode Bypass vulnerability

★ 8 · 2026-01-25
Cedric-Martz/CVE-2025-36911_scan

This script can be used to check if a Bluetooth device is vulnerable to CVE-2025-36911.

★ 3 · 2026-01-17
CVE-2026-33634
MULTI PoC
PoCs 5 ★ 12 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 5 repositories
ugurrates/teampcp-supply-chain-attack

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

★ 12 · 2026-07-28
fevar54/CVE-2026-33634-Scanner

Scanner de IOCs del ataque de cadena de suministro TeamPCP (CVE-2026-33634).

★ 0 · 2026-03-30
AshleyT3/docker-socket-risk-demos

Companion source for YouTube video "Stop Mounting docker.sock — Run Trivy Without Giving Away Root Access — (inspired by CVE-2026-33634)"

★ 0 · 2026-03-31
dfs333/trivysupplychainanalysis

Formally verified, quantitative reconstruction of the Trivy/TeamPCP GitHub Actions supply-chain attack (CVE-2026-33634): a TLA+/TLC incident model, PRISM proba…

★ 0 · 2026-07-16
joaovicdev/EXPLOIT-CVE-2026-33634
★ 0 · 2026-09-21
< Prev Page 26 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.