Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVE-2026-88854
CRITICAL
CVSS 9.3 CRITICAL CWE-89 Published 2026-09-20 PoCs 1 ★ 3 Last push 2026-09-20 (2 weeks, 6 days ago)

Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.

Show 1 repositories
murrez/CVE-2026-88854

CVE-2026-88854 — OrdaSoft Joomla Gallery unauth SQLi PoC (check / mass scan / EXTRACTVALUE read)

★ 3 · 2026-09-20
PoCs 1 ★ 0 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
deepanshu-khurana/CVE-2023-43804
★ 0 · 2026-09-20
PoCs 3 ★ 0 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 3 repositories
HORKimhab/CVE-2026-58231

CVE-2026-58231 Detection & Confirmation Script

★ 0 · 2026-08-17
WildanDeveloper/CVE-2026-58231

Detection & precondition-verification tool for CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter)

★ 0 · 2026-09-20
SAP-system-update/CVE-2026-58231
★ 0 · 2026-09-02
CVE-2023-27163
MULTI PoC
PoCs 24 ★ 32 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
entr0pie/CVE-2023-27163

Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)

★ 32 · 2023-08-09
samh4cks/CVE-2023-27163-InternalProber

A tool to perform port scanning using vulnerable Request-Baskets

★ 5 · 2023-08-28
seanrdev/cve-2023-27163

To assist in enumerating the webserver behind the webserver SSRF CVE-2023-27163

★ 4 · 2023-07-22
hhesenjan/CVE-2023-27163-AND-Mailtrail-v0.53

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53

★ 2 · 2023-08-05
rvzsec/CVE-2023-27163

CVE-2023-27163 - Request Baskets SSRF

★ 2 · 2023-08-09
thomas-osgood/CVE-2023-27163

Golang PoC for CVE-2023-27163 Mailtrail Exploit

★ 2 · 2023-08-14
MasterCode112/CVE-2023-27163

Proof of Concept for Server Side Request Forgery (SSRF) in request-baskets (V<= v.1.2.1)

★ 2 · 2024-01-10
lukehebe/CVE-2023-27163-POC

CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This vulnerab…

★ 2 · 2025-04-18
PoCs 1 ★ 1 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
Reelix/CVE-2026-71217-PoC

A PoC for CVE-2026-71217

★ 1 · 2026-09-20
PoCs 1 ★ 0 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
0Linear/CVE-2026-78844
★ 0 · 2026-09-20
PoCs 2 ★ 4 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 2 repositories
sec-zone/CVE-2026-36213

CVE-2026-36213 | Local Privilege Escalation in MEmu Android Emulator 9.2.7.0 via Insecure Service Binary Permissions | Patched in 9.3.2

★ 4 · 2026-06-11
yzy0okrkv1hngo0r/CVE-2026-36213-poc

CVE-2026-36213: MEmu Android Emulator 9.2.7.0 Local Privilege Escalation

★ 0 · 2026-09-20
PoCs 1 ★ 0 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
CVE-2023-21554
MULTI PoC
PoCs 6 ★ 60 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 6 repositories
zoemurmure/CVE-2023-21554-PoC

CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/

★ 60 · 2023-05-18
3tternp/CVE-2023-21554
★ 28 · 2023-08-21
leongxudong/MSMQ-Vulnerability

Documentation and PoC for CVE-2023-21554 MSMQ Vulnerability

★ 5 · 2026-06-29
shootweb/CVE-2023-21554

CVE-2023-21554 PoC

★ 2 · 2025-10-09
Rahul-Thakur7/CVE-2023-21554
★ 0 · 2024-12-16
TheArtist54/CVE-2023-21554-PoC
★ 0 · 2026-09-20
PoCs 4 ★ 3 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 4 repositories
j4k0m/loader-CVE-2020-14343

A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.

★ 3 · 2022-04-19
Kairo-one/CVE-2020-14343-PyYAML

CVE-2020-14343的payload

★ 0 · 2025-11-29
sijie52/yasa-cve-2020-14343
★ 0 · 2026-01-29
saina15/cve-2020-14343-lab

Controlled vulnerability research and reproduction lab for CVE-2020-14343 in PyYAML

★ 0 · 2026-09-20
CVE-2026-23111
MULTI PoC
PoCs 10 ★ 9 Last push 2026-09-20 (2 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 10 repositories
Knz-source/CVE-2026-23111-POC-noddlenpottato

CVE-2026-23111 nf_tables catchall UAF — unprivileged LPE for Linux 5.10-6.18. Auto-adaptive exploit with KASLR bypass, arbitrary kernel read, and ROP chain. Su…

★ 9 · 2026-08-12
Baba01hacker666/CVE-2026-23111

Linux Kernel nf_tables Use-After-Free (CVE-2026-23111) — LPE PoC

★ 7 · 2026-07-10
0xBlackash/CVE-2026-23111

CVE-2026-23111

★ 4 · 2026-06-09
ishankaru/CVE-2026-23111-nftables-lab

Exposure checker and safe disposable-VM lab for CVE-2026-23111 (Linux nf_tables use-after-free local privilege escalation). Defensive: detection, mitigation, m…

★ 2 · 2026-06-11
bakano98/cve-2026-23111-poc

scuffed PoC for CVE-2026-23111. Made and ran on Linux Kernel 6.12.69

★ 1 · 2026-07-01
vrtlbob/Linux-Kernel-Vulnerabilities-CVE-2026-23111

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break out of th…

★ 1 · 2026-07-02
HORKimhab/CVE-2026-23111

CVE-2026-23111 - Linux - Draft

★ 0 · 2026-06-09
criann/check-cve-2026-23111

Script to check if system are vulnable to cve-2026-23111

★ 0 · 2026-06-11
CVSS 7.4 HIGH CWE-266, CWE-284 Published 2026-09-20 PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

Show 1 repositories
djzzlim/CVE-2026-94036
★ 0 · 2026-09-19
PoCs 3 ★ 4 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 3 repositories
nuPacaChi/-CVE-2021-44790

Thực nghiệm CVE-2021-44790

★ 4 · 2023-12-05
CerberusMrXi/Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architect…

★ 1 · 2026-08-07
CVE-2026-92229
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-09-19 PoCs 1 ★ 5 Last push 2026-09-19 (3 weeks ago)

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Show 1 repositories
murrez/CVE-2026-92229

CVE-2026-92229 — Forminator ≤1.57.2 unauth shortcode exec (current_url / quiz AJAX). Python 3 PoC.

★ 5 · 2026-09-19
PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-2026-84434

PoC for CVE-2026-84434: unauthenticated arbitrary file upload in Gravity Forms ≤3.1.0.4 via hidden File Upload fields. Python check/exploit/mass scan.

★ 0 · 2026-09-19
PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/netty-http-check

CVE-2026-59903 / CVE-2026-33870: offline checker for io.netty:netty-codec-http - its 14 CVEs plus 9 advisories Netty published on 2026-09-10 that the GitHub Ad…

★ 0 · 2026-09-19
PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/async-http-client-check

CVE-2026-85721: offline checker for org.asynchttpclient:async-http-client against all 21 repository-level advisories. The GitHub Advisory Database (Dependabot …

★ 0 · 2026-09-19
PoCs 4 ★ 6 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 4 repositories
sunhuiHi666/CVE-2025-31125

Vite 任意文件读取漏洞POC

★ 6 · 2025-04-01
MuhammadWaseem29/Vitejs-exploit

Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.

★ 0 · 2025-05-03
0xgh057r3c0n/CVE-2025-31125

Vite WASM Import Path Traversal 🛡️

★ 0 · 2025-08-13
harshgupptaa/Path-Transversal-CVE-2025-31125-

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposi…

★ 0 · 2026-09-19
PoCs 1 ★ 6 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 1 repositories
suce0155/CVE-2026-32996

A vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

★ 6 · 2026-09-19
CVSS 8.6 HIGH CWE-79 Published 2026-09-18 PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

Show 1 repositories
prince325/CVE-2026-93659-writeup

Stored XSS in Concrete CMS Community Store leads to admin dashboard takeover

★ 0 · 2026-09-19
CVE-2025-32433
HOTMULTI PoC
PoCs 41 ★ 142 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 8 of 41 repositories
ProDefense/CVE-2025-32433

CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2

★ 142 · 2025-08-02
omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

★ 16 · 2025-08-04
NiteeshPujari/CVE-2025-32433-PoC

CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433

★ 7 · 2025-08-14
m0usem0use/erl_mouse

python script to find vulnerable targets of CVE-2025-32433

★ 6 · 2025-04-19
0xPThree/cve-2025-32433
★ 6 · 2025-04-19
ekomsSavior/POC_CVE-2025-32433
★ 4 · 2025-04-19
darses/CVE-2025-32433

Security research on Erlang/OTP SSH CVE-2025-32433.

★ 3 · 2025-04-19
LemieOne/CVE-2025-32433

Missing Authentication for Critical Function (CWE-306)-Exploit

★ 3 · 2025-04-18
PoCs 1 ★ 0 Last push 2026-09-19 (3 weeks ago)

Fetching description from NVD…

Show 1 repositories
licitrasimone/cve-2026-75157-poc

Standalone authorized universal HTTP PoC for CVE-2026-75157

★ 0 · 2026-09-19
CVSS 8.2 HIGH CWE-89 Published 2026-05-19 PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the TypoScript/Plugin setting disableOverrideDemand not to be enabled.

Show 1 repositories
Shentao83/news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

★ 0 · 2026-09-18
PoCs 2 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 2 repositories
shinigami-777/PoC_CVE-2024-28157

Proof of Concept for CVE-2024-28157

★ 0 · 2025-10-05
Jayesh-Dev21/PoC_CVE-2024-28157

PoC for (CVE-2024-28157) Stored XSS in Jenkins GitBucket Plugin <= 0.8

★ 0 · 2026-09-18
PoCs 2 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 2 repositories
keyuraghao/CVE-2025-20260

First public PoC for CVE-2025-20260 (CVSS 9.8) - a ClamAV PDF-scanning buffer overflow, with core-dump analysis.

★ 0 · 2026-09-18
< Prev Page 28 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.