Fetching description from NVD…
Show 1 repositories
CVE-2025-38502 Linux LPE. BPF cgroup local storage OOB via tail calls. Affected kernels: 5.9–5.15.191, 5.16–6.1.150, 6.2–6.6.104, 6.7–6.12.45, 6.13–6.16.0; fix…
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
CVE-2025-38502 Linux LPE. BPF cgroup local storage OOB via tail calls. Affected kernels: 5.9–5.15.191, 5.16–6.1.150, 6.2–6.6.104, 6.7–6.12.45, 6.13–6.16.0; fix…
Fetching description from NVD…
Security advisory and research notes for CVE-2026-18464 affecting the WP Maps Pro WordPress plugin.
Fetching description from NVD…
Security advisory and research notes for CVE-2026-16265 affecting the WP Maps WordPress plugin.
Fetching description from NVD…
Full ML-KEM-1024 key recovery from a partial Fujisaki-Okamoto comparison in wolfSSL (CVE-2026-6330 NEON, CVE-2026-10097 AVX2)
Fetching description from NVD…
CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on Maven Central?…
Fetching description from NVD…
Sample project that uses VEX to supress CVE-2024-29415.
Maintained fork of node-ip with the unpatched SSRF advisory (CVE-2024-29415) fixed
Fetching description from NVD…
PoC for CVE-2026-1961 — command injection in Foreman's WebSocket proxy (lib/ws_proxy.rb) via unsanitized compute resource hostname, leading to RCE as the forem…
Fetching description from NVD…
Exploit and detect tools for CVE-2020-0688
cve-2020-0688
cve-2020-0688
CVE-2020-0688_EXP Auto trigger payload & encrypt method
CVE-2020-0688 - Exchange
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
Fetching description from NVD…
Ruby/PHP upb Any-recursion audit: falsified vs CVE-2026-0994 bug class
Fetching description from NVD…
macOS < 26.6 local privilege escalation PoC
SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover.
CVE-2026-93453 Exploit — SOGo password reset link poisoning via attacker-controlled Origin header, enabling password reset token interception and account takeo…
Fetching description from NVD…
Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769
Fetching description from NVD…
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
cve-2009-3103
CVE-2009-3103 ms09-050
MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow exploit with built-in scanner, arch auto-detection, and standalone reverse shell payloads for x86/x64. …
Fetching description from NVD…
CVE-2026-18574 - Draft or TODO
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
CVE-2026-91843 - Draft or TODO
Fetching description from NVD…
CVE-2026-77179 - Draft or TODO
Fetching description from NVD…
Exploit information for CVE-2023-26609
Fetching description from NVD…
Exploit information for CVE-2023-26602
Fetching description from NVD…
Information on the security content of Apple software updates
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.
CVE-2026-87930 Joomla Multi-CVE RCE suite — authorized testing only
Fetching description from NVD…
CVE-2026-27540 WWLC WordPress unauth upload RCE suite — authorized testing only
Fetching description from NVD…
PoC and lab reproduction for CVE-2026-88533
Fetching description from NVD…
macOS/ XNU kernel buffer overflow. Introduced in macOS 14.0 (xnu-10002.1.13), fixed in macOS 14.5 (xnu-10063.121.3)
CVE-2024-27815 - XNU kernel heap buffer overflow in sbconcat_mbufs()
Fetching description from NVD…
Fetching description from NVD…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.