Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
351PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

69 results

CVSS 7.5 HIGH CWE-917, CWE-1333 Published 2026-06-03 PoCs 1 ★ 0 Last push 2026-08-03 (2 months, 1 week ago)

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

Show 1 repositories
CVSS 8.3 HIGH CWE-416 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-08-03 (2 months, 1 week ago)

Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Show 1 repositories
CVSS 8.3 HIGH CWE-472 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-08-03 (2 months, 1 week ago)

Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Show 1 repositories
CVSS 7.6 HIGH CWE-79 Published 2026-05-29 PoCs 1 ★ 0 Last push 2026-08-02 (2 months, 1 week ago)

A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project tags and popovers on administrative detail views (such as campaigns, emails, or forms), user-supplied project names are rendered without proper sanitization. An authenticated user with permissions to create or edit projects can exploit this to inject malicious script payloads. When an administrative user views an entity associated with a compromised project and hovers over its tag, the injected script executes within the context of their active browser session. This could allow an attacker to perform administrative actions on behalf of the victim, alter system configurations, or exfiltrate sensitive data.

Show 1 repositories
aj2108/CVE-2026-9809

CVE-2026-9809 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting Mautic 7 (versions 7.0.0 through 7.1.1).

★ 0 · 2026-08-02
CVSS 7.1 HIGH CWE-79 Published 2026-07-20 PoCs 1 ★ 0 Last push 2026-08-01 (2 months, 1 week ago)

The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in the response body served with an HTML content type, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of a logged-in user with `edit_pages` capability (Editor or higher) who is tricked into following a crafted link.

Show 1 repositories
aj2108/CVE-2026-9833
★ 0 · 2026-08-01
CVSS 7.8 HIGH Published 2026-06-09 PoCs 1 ★ 1 Last push 2026-07-25 (2 months, 2 weeks ago)

Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.

Show 1 repositories
0xbekoo/CVE-2026-8863

Hashes and shim versions for the UEFI Secure Boot shims affected by CVE-2026-8863

★ 1 · 2026-07-25
CVSS 8.8 HIGH CWE-787 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-07-21 (2 months, 2 weeks ago)

Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Show 1 repositories
Mofarthim/CVE-2026-9973-exploit
★ 0 · 2026-07-21
CVSS 7.5 HIGH CWE-22 Published 2026-06-06 PoCs 1 ★ 0 Last push 2026-07-06 (3 months ago)

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

Show 1 repositories
shinthink/CVE-2026-9290

Pre-auth Local File Inclusion in WP User Manager <= 2.9.17 via path traversal in tab parameter (CVSS 7.5)

★ 0 · 2026-07-06
CVSS 8.9 HIGH CWE-119, CWE-121 Published 2026-05-18 PoCs 1 ★ 0 Last push 2026-06-21 (3 months, 2 weeks ago)

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of the argument msgAuthenticationParameters results in stack-based buffer overflow. The attack may be initiated remotely. The patch is named 0c957ec03054eb6c8205e9c9d1d05d90ada3898c. It is suggested to install a patch to address this issue. Two separate issue reports were submitted to the project. Their processing was merged as a duplicate.

Show 1 repositories
Hunt-Benito/lwip-snmpv3-stack-overflow-cve-2026-8836-critical-embedded-rce

CVE-2026-8836 — lwIP SNMPv3 stack-based buffer overflow PoC (CVSS 9.8)

★ 0 · 2026-06-21
CVSS 8.5 HIGH CWE-22, CWE-269, CWE-284, CWE-732 Published 2026-05-28 PoCs 1 ★ 0 Last push 2026-05-30 (4 months, 1 week ago)

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the service does not check the caller's privileges before running file deletion commands, a low-privileged local user can exploit this to delete arbitrary files with system authority.

Show 1 repositories
ugvxb/CVE-2026-9789

A critical local privilege escalation vulnerability has been discovered in Acer NitroSense software (PSAdminAgent.exe). The vulnerability allows any authentica…

★ 0 · 2026-05-30
CVSS 8.7 HIGH CWE-288, CWE-306 Published 2026-05-28 PoCs 1 ★ 1 Last push 2026-05-29 (4 months, 1 week ago)

Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web interface. This enables an attacker to brute-force valid credentials via SSH. Successful exploitation could allow an attacker with adjacent network access to obtain administrative credentials through unrestricted authentication attempts and subsequently gain full administrative access to the device, impacting system confidentiality, integrity, and availability.

Show 1 repositories
itzmetanjim/cve-2026-8697

writeup

★ 1 · 2026-05-29
CVSS 8.8 HIGH CWE-94 Published 2026-05-27 PoCs 2 ★ 1 Last push 2026-05-28 (4 months, 1 week ago)

The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.3.5 This is due to the 'wpcode' custom post type being registered without a custom capability_type or capability restrictions in the wpcode_register_post_type() function, allowing WordPress core to fall back to standard post capabilities for all creation paths including XML-RPC. This makes it possible for authenticated attackers, with author-level access and above, to create and publish executable PHP snippet posts via XML-RPC wp.newPost, which are then executed server-side via eval() in the run_eval() function when the snippet is rendered through the [wpcode] shortcode.

Show 2 repositories
funixone/EXPLOIT-CVE-2026-8832
★ 1 · 2026-05-28
funixone/EXPLOIT-CVE-2026-8832-

EXPLOIT CVE-2026-8832

★ 0 · 2026-05-28
CVSS 8.8 HIGH CWE-269 Published 2026-05-22 PoCs 1 ★ 1 Last push 2026-05-23 (4 months, 2 weeks ago)

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's meta via `update_user_meta()` without any key whitelist or blocklist, allowing the `wp_capabilities` user meta key to be overwritten after `wp_insert_user()` has already assigned a safe role. This makes it possible for unauthenticated attackers to register a new account with full administrator-level privileges by supplying `custom_meta[wp_capabilities][administrator]=1`. Exploitation requires that user registration is enabled on the site and that at least one page exposes the Login/Register widget, which publishes the required `easy_elements_nonce` into the page DOM where it can be retrieved by any unauthenticated visitor via a simple GET request.

Show 1 repositories
xxconi/CVE-2026-9018

Unauthenticated Privilege Escalation CVE-2026-9018: Easy Elements for Elementor

★ 1 · 2026-05-23
CVSS 8.8 HIGH CWE-22, CWE-434 Published 2020-09-25 PoCs 1 ★ 0 Last push 2021-07-13 (5 years, 2 months ago) Discovered 2026-10-09 03:16

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /settings/?format=../ URIs to pages/settings.inc.php.

Show 1 repositories
ynsmroztas/CVE-2020-25134

CVE-2020-25134 Authenticated Local File Inclusion in settings/format

★ 0 · 2021-07-13
CVSS 7.8 HIGH Published 2020-03-12 PoCs 1 ★ 0 Last push 2021-07-12 (5 years, 2 months ago) Discovered 2026-10-09 03:16

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.

Show 1 repositories
vinhthp1712/CVE-2020-0887
★ 0 · 2021-07-12
CVSS 8.8 HIGH CWE-78 Published 2020-05-22 PoCs 1 ★ 0 Last push 2021-07-09 (5 years, 3 months ago) Discovered 2026-10-09 03:16

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

Show 1 repositories
b510/CVE-2020-1956

CVE-2020-1956

★ 0 · 2021-07-09
CVSS 8.8 HIGH Published 2020-09-03 PoCs 1 ★ 0 Last push 2021-06-03 (5 years, 4 months ago) Discovered 2026-10-09 03:16

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

Show 1 repositories
r90tpass/CVE-2020-24949

PHPFusion 9.03.50 - Remote Code Execution

★ 0 · 2021-06-03
CVSS 8.8 HIGH CWE-78 Published 2020-07-17 PoCs 1 ★ 8 Last push 2021-06-01 (5 years, 4 months ago) Discovered 2026-10-09 03:16

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary commands as the user running airflow worker/scheduler (depending on the executor in use). If you already have examples disabled by setting load_examples=False in the config then you are not vulnerable.

Show 1 repositories
pberba/CVE-2020-11978

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

★ 8 · 2021-06-01
CVSS 8.8 HIGH CWE-352 Published 2021-01-19 PoCs 1 ★ 0 Last push 2021-05-02 (5 years, 5 months ago) Discovered 2026-10-09 03:16

A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.

Show 1 repositories
DXY0411/CVE-2020-23342
★ 0 · 2021-05-02
< Prev Page 3 / 3

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.