Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
CVE-2025-41249
CVE-2024-36774
CVE-2022-21812
8 contacts in last 24h
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
11105 results
PoCs 30
★ 353
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 8 of 30 repositories
hktalent/spring-spel-0day-poc
spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
★ 353 · 2023-03-05
kh4sh3i/Spring-CVE
This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed …
★ 14 · 2022-03-31
PoCs 62
★ 223
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 8 of 62 repositories
PoCs 7
★ 58
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 7 repositories
PoCs 3
★ 155
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 3 repositories
tpt11fb/SpringVulScan
burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977
★ 155 · 2023-01-23
PoCs 6
★ 4291
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 6 repositories
zhzyker/exphub
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020…
★ 4291 · 2021-04-04
PoCs 2
★ 0
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 2 repositories
captain-woof/cve-2017-12629
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener com…
★ 0 · 2025-08-01
PoCs 7
★ 55
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 7 repositories
4nth0ny1130/shisoserial
一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
★ 24 · 2022-07-06
pizza-power/CVE-2016-4437
Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key
★ 2 · 2024-06-29
PoCs 22
★ 380
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 8 of 22 repositories
I-Rinka/BIT-EternalBlue-for-macOS_Linux
Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.
★ 4 · 2021-05-18
PoCs 15
★ 121
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 8 of 15 repositories
PoCs 6
★ 95
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 6 repositories
PoCs 11
★ 201
Last push 2026-10-09 (21 hours, 29 minutes ago)
Fetching description from NVD…
Show 8 of 11 repositories
mpgn/Rails-doubletap-RCE
RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)
★ 132 · 2023-01-19
kailing0220/CVE-2019-5418
Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render file来渲染应用之外的视图,我们可以通过修改访问某控制器的请求包,通过“…/…/…/…/”来达到路径穿越的目的,然后再…
★ 2 · 2022-10-17
PoCs 4
★ 8
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 4 repositories
PoCs 9
★ 21
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 9 repositories
geniuszly/CVE-2019-9193
is a PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in specific versions of PostgreSQL (9.3 - 11.7)
★ 4 · 2024-10-06
jhnhnck/CVE-2019-9193
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
★ 0 · 2026-09-11
PoCs 18
★ 30
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 18 repositories
PoCs 40
★ 35
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
Black1hp/mongobleed-scanner
MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool
★ 35 · 2025-12-28
cybertechajju/CVE-2025-14847_Expolit
a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…
★ 34 · 2025-12-27
PoCs 4
★ 10
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 4 repositories
PoCs 28
★ 1833
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 28 repositories
kriskhub/CVE-2019-11043
This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.
★ 14 · 2020-05-25
PoCs 16
★ 12
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 16 repositories
Unix13/metasploitable2
PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured…
★ 4 · 2018-07-11
PoCs 2
★ 2
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 2 repositories
glowbase/CVE-2020-35476
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter.
★ 2 · 2022-08-06
PoCs 73
★ 2373
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 73 repositories
einaros/heartbleed-tools
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
★ 98 · 2014-06-18
mpgn/heartbleed-PoC
:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:
★ 85 · 2021-02-20
PoCs 42
★ 533
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 42 repositories
epi052/cve-2018-15473
Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473
★ 117 · 2024-04-29
PoCs 11
★ 25
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 11 repositories
r0lh/CVE-2020-7247
Proof Of Concept Exploit for CVE-2020-7247 (Remote Execution on OpenSMTPD < 6.6.2
★ 5 · 2020-02-18
PoCs 11
★ 142
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 of 11 repositories
PoCs 8
★ 73
Last push 2026-10-09 (21 hours, 30 minutes ago)
Fetching description from NVD…
Show 8 repositories
CVSS 7.5 HIGH
CWE-22
Published 2017-09-28
PoCs 1
★ 0
Last push 2026-10-09 (21 hours, 30 minutes ago)
Discovered 2026-10-09 03:16
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.