Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
12 contacts in last 24h
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
11117 results
CVSS 9.3 CRITICAL
CWE-89
Published 2026-09-20
PoCs 1
★ 3
Last push 2026-09-20 (2 weeks, 6 days ago)
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.
Show 1 repositories
murrez/CVE-2026-88854
CVE-2026-88854 — OrdaSoft Joomla Gallery unauth SQLi PoC (check / mass scan / EXTRACTVALUE read)
★ 3 · 2026-09-20
PoCs 1
★ 0
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 3
★ 0
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 3 repositories
PoCs 24
★ 32
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 24 repositories
lukehebe/CVE-2023-27163-POC
CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerab…
★ 2 · 2025-04-18
PoCs 1
★ 1
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 4
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 2 repositories
sec-zone/CVE-2026-36213
CVE-2026-36213 | Local Privilege Escalation in MEmu Android Emulator 9.2.7.0 via Insecure Service Binary Permissions | Patched in 9.3.2
★ 4 · 2026-06-11
PoCs 1
★ 0
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
PoCs 6
★ 60
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 6 repositories
PoCs 4
★ 3
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 4 repositories
j4k0m/loader-CVE-2020-14343
A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.
★ 3 · 2022-04-19
PoCs 10
★ 9
Last push 2026-09-20 (2 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 10 repositories
ishankaru/CVE-2026-23111-nftables-lab
Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection, mitigation, m…
★ 2 · 2026-06-11
CVSS 7.4 HIGH
CWE-266, CWE-284
Published 2026-09-20
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
Show 1 repositories
PoCs 3
★ 4
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 3 repositories
CVSS 9.1 CRITICAL
CWE-94
Published 2026-09-19
PoCs 1
★ 5
Last push 2026-09-19 (3 weeks ago)
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Show 1 repositories
murrez/CVE-2026-92229
CVE-2026-92229 — Forminator ≤1.57.2 unauth shortcode exec (current_url / quiz AJAX). Python 3 PoC.
★ 5 · 2026-09-19
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 1 repositories
murrez/CVE-2026-84434
PoC for CVE-2026-84434: unauthenticated arbitrary file upload in Gravity Forms ≤3.1.0.4 via hidden File Upload fields. Python check/exploit/mass scan.
★ 0 · 2026-09-19
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 1 repositories
xiaoqiMikko/netty-http-check
CVE-2026-59903 / CVE-2026-33870: offline checker for io.netty:netty-codec-http - its 14 CVEs plus 9 advisories Netty published on 2026-09-10 that the GitHub Ad…
★ 0 · 2026-09-19
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 1 repositories
xiaoqiMikko/async-http-client-check
CVE-2026-85721: offline checker for org.asynchttpclient:async-http-client against all 21 repository-level advisories. The GitHub Advisory Database (Dependabot …
★ 0 · 2026-09-19
PoCs 4
★ 6
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 4 repositories
MuhammadWaseem29/Vitejs-exploit
Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.
★ 0 · 2025-05-03
PoCs 1
★ 6
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 1 repositories
suce0155/CVE-2026-32996
A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.
★ 6 · 2026-09-19
CVSS 8.6 HIGH
CWE-79
Published 2026-09-18
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
Show 1 repositories
PoCs 41
★ 142
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 8 of 41 repositories
NiteeshPujari/CVE-2025-32433-PoC
CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433
★ 7 · 2025-08-14
PoCs 1
★ 0
Last push 2026-09-19 (3 weeks ago)
Fetching description from NVD…
Show 1 repositories
CVSS 8.2 HIGH
CWE-89
Published 2026-05-19
PoCs 1
★ 0
Last push 2026-09-18 (3 weeks, 1 day ago)
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.
Show 1 repositories
PoCs 2
★ 0
Last push 2026-09-18 (3 weeks, 1 day ago)
Fetching description from NVD…
Show 2 repositories
PoCs 2
★ 0
Last push 2026-09-18 (3 weeks, 1 day ago)
Fetching description from NVD…
Show 2 repositories
keyuraghao/CVE-2025-20260
First public PoC for CVE-2025-20260 (CVSS 9.8) - a ClamAV PDF-scanning buffer overflow, with core-dump analysis.
★ 0 · 2026-09-18
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.