Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

60 results

CVE-2026-9277
CRITICAL
CVSS 9.2 CRITICAL CWE-77, CWE-78 Published 2026-05-22 PoCs 1 ★ 2 Last push 2026-07-12 (2 months, 3 weeks ago)

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\n, \r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.

Show 1 repositories
DylanZahedi/CVE-2026-9277
★ 2 · 2026-07-12
CVE-2026-8713
CRITICAL
CVSS 9.1 CRITICAL CWE-22 Published 2026-06-19 PoCs 1 ★ 4 Last push 2026-07-06 (3 months ago)

The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The attack requires a published Avada form configured to save entries to the database; an unauthenticated attacker submits a path-traversal payload via the wp_ajax_nopriv_fusion_form_submit_ajax handler while also controlling the fusion_privacy_expiration_interval and privacy_expiration_action fields to force an immediate 'delete' cleanup, causing the planted entry to be automatically processed by the Fusion_Form_DB_Privacy shutdown-hook routine without any administrator interaction.

Show 1 repositories
shinthink/CVE-2026-8713

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

★ 4 · 2026-07-06
CVE-2026-9691
CRITICAL
CVSS 9.8 CRITICAL CWE-502 Published 2026-06-15 PoCs 1 ★ 0 Last push 2026-06-17 (3 months, 3 weeks ago)

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Show 1 repositories
izxci/CVE-2026-9691

CVE-2026-9691: Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 Unauthenticated PHP Object Injection PoC, Patch Anal…

★ 0 · 2026-06-17
CVE-2026-8809
CRITICAL
CVSS 9.8 CRITICAL CWE-269 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-06-12 (3 months, 3 weeks ago)

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that silently discards all validation errors not prefixed with acfe:. This makes it possible for unauthenticated attackers to suppress both the role allow-list validation error added by acfe_field_user_roles::validate_front_value() and the administrator-role capability guard error added by acfe_module_form_action_user::validate_action(), causing wp_insert_user() to execute with an attacker-supplied administrator role argument and resulting in the creation of a new administrator-level user account. Exploitation requires the target site to expose a public ACFE frontend form configured with a Create User action that maps a role field.

Show 1 repositories
izxci/CVE-2026-8809

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

★ 0 · 2026-06-12
CVE-2026-9067
CRITICAL
CVSS 9.1 CRITICAL CWE-434 Published 2026-06-10 PoCs 1 ★ 3 Last push 2026-06-10 (3 months, 4 weeks ago)

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos.

Show 1 repositories
Polosss/By-Poloss..-..CVE-2026-9067

Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]

★ 3 · 2026-06-10
CVE-2026-9560
CRITICAL
CVSS 9.4 CRITICAL CWE-78, CWE-267, CWE-270, CWE-648 Published 2026-05-26 PoCs 1 ★ 0 Last push 2026-06-01 (4 months, 1 week ago)

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

Show 1 repositories
HORKimhab/CVE-2026-9560

CVE-2026-9560 - Draft

★ 0 · 2026-06-01
CVE-2020-24148
CRITICAL
CVSS 9.1 CRITICAL CWE-918 Published 2021-07-07 PoCs 1 ★ 5 Last push 2021-07-12 (5 years, 2 months ago) Discovered 2026-10-09 03:16

Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action.

Show 1 repositories
dwisiswant0/CVE-2020-24148

CVE-2020-24148 Proof-of-Concept

★ 5 · 2021-07-12
CVE-2020-7115
CRITICAL
CVSS 9.8 CRITICAL CWE-306 Published 2020-06-03 PoCs 1 ★ 1 Last push 2021-07-03 (5 years, 3 months ago) Discovered 2026-10-09 03:16

The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

Show 1 repositories
Retr02332/CVE-2020-7115

Create your malicious engine in seconds

★ 1 · 2021-07-03
CVE-2020-13957
CRITICAL
CVSS 9.8 CRITICAL CWE-863 Published 2020-10-13 PoCs 1 ★ 1 Last push 2021-06-06 (5 years, 4 months ago) Discovered 2026-10-09 03:16

Apache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 prevents some features considered dangerous (which could be used for remote code execution) to be configured in a ConfigSet that's uploaded via API without authentication/authorization. The checks in place to prevent such features can be circumvented by using a combination of UPLOAD/CREATE actions.

Show 1 repositories
s-index/CVE-2020-13957

Apache Solr RCE CVE-2020-13957

★ 1 · 2021-06-06
CVE-2020-28018
CRITICAL
CVSS 9.8 CRITICAL CWE-416 Published 2021-05-06 PoCs 1 ★ 7 Last push 2021-05-15 (5 years, 4 months ago) Discovered 2026-10-09 03:16

Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

Show 1 repositories
dorkerdevil/CVE-2020-28018

exim use after free exploit and detection

★ 7 · 2021-05-15
< Prev Page 3 / 3

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.