Fetching description from NVD…
Show 1 repositories
ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)
Fetching description from NVD…
Craft CMS CVE-2026-72778 condition.config RCE PoC
Fetching description from NVD…
Craft CMS CVE-2026-55794 signed-referrer SSTI PoC
Fetching description from NVD…
Craft CMS CVE-2026-72781 Twig sandbox escape RCE PoC
Fetching description from NVD…
Craft CMS CVE-2026-33157 filter-hud behavior-injection RCE PoC
Fetching description from NVD…
Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CV…
Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-2185…
Security scanner auditing Claude Code environments for CVE-2026-21852 pre-trust execution, hook hijacking, and eBPF lockdown.
Fetching description from NVD…
Redacted notes on CVE-2026-28618 / StreamBox APV lab — heap write into a session object via FRAME height mismatch
Fetching description from NVD…
Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a crafted WebM f…
The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.
Technical details, proof of concept, and responsible disclosure timeline for CVE-2026-93528 (Unauthenticated Order Data Disclosure in NP Quote Request for WooC…
SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.
ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.
Fetching description from NVD…
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
Arbitrary File Upload Under
Fetching description from NVD…
Example how to use this CVE
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
PoC exploit and scanner for CVE-2026-89026, targeting the Issabel PBXAPI authentication vulnerability
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Netcore NBR200V2 traceroute command injection PoC (CVE-2026-94095); ubus JSON-RPC -> system() root RCE; for authorized testing
Fetching description from NVD…
CVE-2025-6325 + CVE-2025-6327 — King Addons for Elementor <= 51.1.36 DUAL EXPLOIT PoC (Unauthenticated Privilege Escalation + Arbitrary File Upload)
Fetching description from NVD…
Security research lab — Unauthenticated RCE via insecure deserialization in ComfyUI v0.23.0 (CVSS 9.8). Isolated Docker environment, technical analysis and doc…
Fetching description from NVD…
Fetching description from NVD…
Forensic Analysis and Local Replication of the OpenAI-Artifactory Privilege Escalation Incident (CVE-2026-65616)
Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)
Fetching description from NVD…
The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
CVE-2026-8932
CVE-2026-8932 PoC - incomplete mTLS config matching in conn reuse
Fetching description from NVD…
A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF …
RTF Crash POC Python 3.11 Windows 10
POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption
test of exploit for CVE-2023-21716
Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption
This is an exploit file which is used to check CVE-2021-21716 vulnerability
Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar
Fetching description from NVD…
CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5
Fetching description from NVD…
CVE-2026-49179: Active Directory WriteSPNScript Command Injection
Fetching description from NVD…
This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692
Bootloader unlock using CVE-2022-38694 for Anbernic Unisoc T820 devices
CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices
Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694
rooting an ATOZEE P12 on Android 14 using CVE-2022-38694 — because fastboot oem unlock said no, so we found another way.
This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694
Bootloader unlock (CVE-2022-38694) & root guide for Realme C53 / RMX3760 (Unisoc T612)
Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.
Fetching description from NVD…
A bash script demonstrating the manual exploitation of CVE-2016-10204 against a target endpoint, leading to upload of a php webshell.
Unauthenticated SQL injection to RCE exploit for ZoneMinder 1.29/1.30 (CVE-2016-10204, EDB-41239). Single-command SQLi to webshell to reverse shell PoC in Pyth…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.