Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
346PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 2 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
abraxas/CVE-2025-38502-Linux-LPE

CVE-2025-38502 Linux LPE. BPF cgroup local storage OOB via tail calls. Affected kernels: 5.9–5.15.191, 5.16–6.1.150, 6.2–6.6.104, 6.7–6.12.45, 6.13–6.16.0; fix…

★ 2 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
ghoxtbyte/CVE-2026-18464

Security advisory and research notes for CVE-2026-18464 affecting the WP Maps Pro WordPress plugin.

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
ghoxtbyte/CVE-2026-16265

Security advisory and research notes for CVE-2026-16265 affecting the WP Maps WordPress plugin.

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
007bsd/ml-kem-key-recovery

Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/jetty-line-check

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on Maven Central?…

★ 0 · 2026-09-18
PoCs 2 ★ 1 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 2 repositories
felipecruz91/node-ip-vex

Sample project that uses VEX to supress CVE-2024-29415.

★ 1 · 2024-07-05
bybraveHQ/ip2

Maintained fork of node-ip with the unpatched SSRF advisory (CVE-2024-29415) fixed

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
kalnux/CVE-2026-1961-foreman-poc

PoC for CVE-2026-1961 — command injection in Foreman's WebSocket proxy (lib/ws_proxy.rb) via unsanitized compute resource hostname, leading to RCE as the forem…

★ 0 · 2026-09-18
CVE-2020-0688
HOTMULTI PoC
PoCs 24 ★ 353 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 24 repositories
zcgonvh/CVE-2020-0688

Exploit and detect tools for CVE-2020-0688

★ 353 · 2020-03-21
Ridter/cve-2020-0688

cve-2020-0688

★ 327 · 2023-07-04
random-robbie/cve-2020-0688

cve-2020-0688

★ 165 · 2020-02-26
Yt1g3r/CVE-2020-0688_EXP

CVE-2020-0688_EXP Auto trigger payload & encrypt method

★ 144 · 2020-02-27
Jumbo-WJB/CVE-2020-0688

CVE-2020-0688 - Exchange

★ 66 · 2020-02-27
onSec-fr/CVE-2020-0688-Scanner

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.

★ 37 · 2026-09-18
w4fz5uck5/cve-2020-0688-webshell-upload-technique

cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output

★ 23 · 2023-09-12
MrTiz/CVE-2020-0688

Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys

★ 22 · 2021-06-06
PoCs 1 ★ 1 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
Vardhan0257/upb-any-recursion-audit

Ruby/PHP upb Any-recursion audit: falsified vs CVE-2026-0994 bug class

★ 1 · 2026-09-18
PoCs 1 ★ 21 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
andrd3v/CVE-2026-43783

macOS < 26.6 local privilege escalation PoC

★ 21 · 2026-09-18
CVSS 8.7 HIGH CWE-640 Published 2026-09-18 PoCs 1 ★ 2 Last push 2026-09-18 (3 weeks, 1 day ago)

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.

Show 1 repositories
Faceless0x7/CVE-2026-93453

CVE-2026-93453 Exploit — SOGo password reset link poisoning via attacker-controlled Origin header, enabling password reset token interception and account takeo…

★ 2 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
isukasanuj/CVE-2026-85769

Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769

★ 0 · 2026-09-18
CVE-2009-3103
MULTI PoC
PoCs 6 ★ 4 Last push 2026-09-18 (3 weeks, 1 day ago)

Fetching description from NVD…

Show 6 repositories
Sic4rio/CVE-2009-3103---srv2.sys-SMB-Code-Execution-Python-MS09-050-

Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)

★ 4 · 2024-05-05
sooklalad/ms09050

cve-2009-3103

★ 1 · 2017-01-17
sec13b/ms09-050_CVE-2009-3103

CVE-2009-3103 ms09-050

★ 0 · 2024-05-03
afifudinmtop/CVE-2009-3103
★ 0 · 2026-01-26
bytejmp/MS09-050

MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow exploit with built-in scanner, arch auto-detection, and standalone reverse shell payloads for x86/x64. …

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-18574

CVE-2026-18574 - Draft or TODO

★ 0 · 2026-09-18
CVE-2026-91843
CRITICAL
CVSS 9.8 CRITICAL CWE-121 Published 2026-09-16 PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 2 days ago)

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

Show 1 repositories
HORKimhab/CVE-2026-91843

CVE-2026-91843 - Draft or TODO

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-18 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-77179

CVE-2026-77179 - Draft or TODO

★ 0 · 2026-09-18
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
D1G17/CVE-2023-26609

Exploit information for CVE-2023-26609

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
D1G17/CVE-2023-26602

Exploit information for CVE-2023-26602

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
OwenPawl/CVE-2026-84600

Information on the security content of Apple software updates

★ 0 · 2026-09-17
CVE-2026-87930
CRITICAL
CVSS 9.2 CRITICAL CWE-502 Published 2026-09-09 PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.

Show 1 repositories
winrarzipsexploit/CVE-2026-87930

CVE-2026-87930 Joomla Multi-CVE RCE suite — authorized testing only

★ 1 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
winrarzipsexploit/CVE-2026-27540

CVE-2026-27540 WWLC WordPress unauth upload RCE suite — authorized testing only

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
HEMLOCK-LYK/CVE-2026-88533

PoC and lab reproduction for CVE-2026-88533

★ 0 · 2026-09-17
PoCs 2 ★ 51 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 2 repositories
jprx/CVE-2024-27815

macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3)

★ 51 · 2025-07-18
nomnomheapnom/CVE-2024-27815

CVE-2024-27815 - XNU kernel heap buffer overflow in sbconcat_mbufs()

★ 0 · 2026-09-17
PoCs 1 ★ 0 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 1 Last push 2026-09-17 (3 weeks, 2 days ago)

Fetching description from NVD…

Show 1 repositories
< Prev Page 29 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.