Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 5 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
mdshoaibuddinchanda/zombieguard

ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)

★ 5 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
TRX-0/CVE-2026-72778-craftcms-rce

Craft CMS CVE-2026-72778 condition.config RCE PoC

★ 0 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
TRX-0/CVE-2026-55794-craftcms-ssti

Craft CMS CVE-2026-55794 signed-referrer SSTI PoC

★ 0 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
TRX-0/CVE-2026-72781-craftcms-sandbox-rce

Craft CMS CVE-2026-72781 Twig sandbox escape RCE PoC

★ 0 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
TRX-0/CVE-2026-33157-craftcms-rce

Craft CMS CVE-2026-33157 filter-hud behavior-injection RCE PoC

★ 0 · 2026-09-21
PoCs 4 ★ 24 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 4 repositories
atiilla/CVE-2026-21852-PoC
★ 24 · 2026-02-27
TreRB/ai-ide-config-guard

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CV…

★ 0 · 2026-04-20
Perufitlife/dotclaude-security

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-2185…

★ 0 · 2026-06-21
abhishek2512mishra/claude-code-security-audit

Security scanner auditing Claude Code environments for CVE-2026-21852 pre-trust execution, hook hijacking, and eBPF lockdown.

★ 0 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
raafatabualazm/streambox-cve-2026-28618

Redacted notes on CVE-2026-28618 / StreamBox APV lab — heap write into a session object via FRAME height mismatch

★ 0 · 2026-09-21
PoCs 1 ★ 6 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
devrodT2/CVE-2026-28609-matroska-pcm-oob

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a crafted WebM f…

★ 6 · 2026-09-21
CVSS 3.7 LOW CWE-200 Published 2026-09-23 PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an order's details, allowing unauthenticated attackers to view another customer's order using the order's key.

Show 1 repositories
muradislamzada/CVE-2026-93528

Technical details, proof of concept, and responsible disclosure timeline for CVE-2026-93528 (Unauthenticated Order Data Disclosure in NP Quote Request for WooC…

★ 1 · 2026-09-21
CVSS 5.4 MEDIUM CWE-269 Published 2026-09-20 PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acquired SmartLife application authentication credentials, an attacker can directly complete registration using any arbitrary email address via the backend interface /account/person/signup.serv. Email ownership is not verified prior to registration.

Show 1 repositories
minanagehsalalma/zte-smartlife-app-pwned

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

★ 0 · 2026-09-21
PoCs 3 ★ 2 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 3 repositories
shinthink/CVE-2026-14894

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

★ 2 · 2026-07-16
1beelze/CVE-2026-14894
★ 0 · 2026-07-16
Nxploited/CVE-2026-14894

Arbitrary File Upload Under

★ 0 · 2026-09-21
PoCs 1 ★ 0 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
wtfkimi/CVE-2026-77078

Example how to use this CVE

★ 0 · 2026-09-21
CVE-2026-89026
CRITICAL
CVSS 9.3 CRITICAL CWE-321 Published 2026-09-15 PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

Show 1 repositories
AranFarzami/CVE-2026-89026

PoC exploit and scanner for CVE-2026-89026, targeting the Issabel PBXAPI authentication vulnerability

★ 1 · 2026-09-21
CVSS 8.6 HIGH CWE-74, CWE-77 Published 2026-09-21 PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Show 1 repositories
HackSpeak/CVE-2026-94095

Netcore NBR200V2 traceroute command injection PoC (CVE-2026-94095); ubus JSON-RPC -> system() root RCE; for authorized testing

★ 1 · 2026-09-21
PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
JohenLastGen-JLG/CVE-2025-6325_CVE-2025-6327

CVE-2025-6325 + CVE-2025-6327 — King Addons for Elementor <= 51.1.36 DUAL EXPLOIT PoC (Unauthenticated Privilege Escalation + Arbitrary File Upload)

★ 1 · 2026-09-21
PoCs 2 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 2 repositories
0xdak/CVE-2026-68771_exploit
★ 1 · 2026-08-03
Oscar-Collado/comfyui-CVE-2026-68771-PoC

Security research lab — Unauthenticated RCE via insecure deserialization in ComfyUI v0.23.0 (CVSS 9.8). Isolated Docker environment, technical analysis and doc…

★ 0 · 2026-09-21
PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
jvidhan/autofs-cve-2026-84568
★ 1 · 2026-09-21
PoCs 2 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 2 repositories
alixiacf/rep-openai-artifactory

Forensic Analysis and Local Replication of the OpenAI-Artifactory Privilege Escalation Incident (CVE-2026-65616)

★ 1 · 2026-09-17
alixiacf/hpim-training-lab

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

★ 1 · 2026-09-21
PoCs 1 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
thrilokh-q123/CVE-2025-23134_fixes_code

The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().

★ 1 · 2026-09-21
CVSS 7.5 HIGH CWE-305 Published 2026-07-03 PoCs 2 ★ 1 Last push 2026-09-21 (2 weeks, 5 days ago)

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

Show 2 repositories
0xBlackash/CVE-2026-8932

CVE-2026-8932

★ 1 · 2026-06-26
nimaarek/CVE-2026-8932-PoC

CVE-2026-8932 PoC - incomplete mTLS config matching in conn reuse

★ 0 · 2026-09-21
CVE-2023-21716
MULTI PoC
PoCs 12 ★ 59 Last push 2026-09-21 (2 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 12 repositories
gyaansastra/CVE-2023-21716

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a malicious RTF …

★ 59 · 2026-09-21
Xnuvers007/CVE-2023-21716

RTF Crash POC Python 3.11 Windows 10

★ 46 · 2023-03-07
JMousqueton/CVE-2023-21716

POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption

★ 8 · 2023-04-16
hv0l/CVE-2023-21716_exploit

test of exploit for CVE-2023-21716

★ 6 · 2023-03-24
FeatherStark/CVE-2023-21716
★ 4 · 2023-03-07
RonF98/CVE-2023-21716-POC

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption

★ 4 · 2025-07-07
MojithaR/CVE-2023-21716-EXPLOIT.py

This is an exploit file which is used to check CVE-2021-21716 vulnerability

★ 3 · 2023-11-05
mikesxrs/CVE-2023-21716_YARA_Results

Results of retrohunt for files matching YARA rules from https://github.com/AmgdGocha/Detection-Rules/blob/main/CVE-2023-21716.yar

★ 0 · 2023-03-11
PoCs 2 ★ 4 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 2 repositories
Boreas37/CVE-2026-41452-PoC

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

★ 4 · 2026-08-12
o-sec/CVE-2026-41452-poc
★ 0 · 2026-09-20
PoCs 1 ★ 2 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
overgrowncarrot1/CVE-2026-49179-Active-Directory-WriteSPNScript-Command-Injection

CVE-2026-49179: Active Directory WriteSPNScript Command Injection

★ 2 · 2026-09-20
CVE-2022-38694
HOTMULTI PoC
PoCs 15 ★ 624 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 15 repositories
TomKing062/CVE-2022-38694_unlock_bootloader

This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692

★ 624 · 2025-06-14
TheGammaSqueeze/Bootloader_Unlock_Anbernic_T820

Bootloader unlock using CVE-2022-38694 for Anbernic Unisoc T820 devices

★ 65 · 2025-09-19
LeoChen-CoreMind/spd_flasher

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices

★ 8 · 2026-08-05
AureliusIvan/ubl-itel-s23

Unlock Bootloader for Itel S23 (S665L) / Unisoc T606 using CVE-2022-38694

★ 7 · 2026-03-04
Phlegmelm/CRACK12

rooting an ATOZEE P12 on Android 14 using CVE-2022-38694 — because fastboot oem unlock said no, so we found another way.

★ 5 · 2026-05-14
mutur4/UnisocBootROMs

This is a collection of Unisoc BootROMs dumped from various Unisoc chipsets via CVE-2022-38694

★ 5 · 2026-08-11
Gopartner/realme-c53-unlock-root

Bootloader unlock (CVE-2022-38694) & root guide for Realme C53 / RMX3760 (Unisoc T612)

★ 3 · 2026-08-07
JoshAtticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

★ 3 · 2026-06-03
PoCs 2 ★ 2 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 2 repositories
0xNullComet/CVE-2016-10204_Webshell

A bash script demonstrating the manual exploitation of CVE-2016-10204 against a target endpoint, leading to upload of a php webshell.

★ 2 · 2026-02-11
akash0x00/zoneminder-1.29-1.30-rce-exploit

Unauthenticated SQL injection to RCE exploit for ZoneMinder 1.29/1.30 (CVE-2016-10204, EDB-41239). Single-command SQLi to webshell to reverse shell PoC in Pyth…

★ 0 · 2026-09-20
< Prev Page 27 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.