Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
12New in 24h
345PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
vportal/CVE-2022-22715

Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe

★ 0 · 2026-09-16
CVE-2021-29447
MULTI PoC
PoCs 24 ★ 44 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 24 repositories
motikan2010/CVE-2021-29447

WordPress - Authenticated XXE (CVE-2021-29447)

★ 44 · 2021-10-04
mega8bit/exploit_cve-2021-29447
★ 7 · 2022-11-27
0xRar/CVE-2021-29447-PoC

A proof of concept exploit for a wordpress 5.6 media library vulnerability

★ 6 · 2023-01-31
Vulnmachines/wordpress_cve-2021-29447

WordPress XXE vulnerability

★ 4 · 2021-05-23
M3l0nPan/wordpress-cve-2021-29447

Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.

★ 4 · 2022-11-11
dnr6419/CVE-2021-29447

Wordpress XXE injection 구축 자동화 및 PoC

★ 3 · 2022-01-10
elf1337/blind-xxe-controller-CVE-2021-29447

Arbitrary file read controller based on CVE-2021-29447

★ 3 · 2022-11-11
thomas-osgood/CVE-2021-29447

A Golang program to automate the execution of CVE-2021-29447

★ 3 · 2023-03-28
PoCs 3 ★ 2 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 3 repositories
amusedx/CVE-2026-22686
★ 1 · 2026-01-15
moi404/CVE-2026-22686-RemoteCodeExecution-RCE-PoC

CVE-2026-22686-RemoteCodeExecution-RCE-PoC

★ 0 · 2026-09-16
PoCs 1 ★ 11 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
Ping-2o/ios.CVE-2026-84616-84607

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

★ 11 · 2026-09-16
PoCs 2 ★ 6 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 2 repositories
ByteV0rtex/CVE-2026-65330

CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)

★ 6 · 2026-09-04
csrXamfi/CVE-2026-65330

My first CVE

★ 1 · 2026-09-16
PoCs 1 ★ 1 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
anirbala98/CVE-2022-4140

WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read

★ 1 · 2026-09-16
PoCs 1 ★ 1 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
anirbala98/CVE-2025-57231

Docmost < 0.22.0 - Arbitrary File Read

★ 1 · 2026-09-16
CVE-2026-49975
MULTI PoC
PoCs 14 ★ 29 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 8 of 14 repositories
mrx-arafat/CVE-2026-49975-POC

HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)

★ 29 · 2026-06-04
EQSTLab/CVE-2026-49975

HTTP/2 Bomb

★ 14 · 2026-06-25
fevar54/Proof-of-Concept-POC---CVE-2026-49975-HTTP-2-Bomb-

PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.

★ 6 · 2026-06-03
LSG-PolarBear/CVE-2026-49975

CVE-2026-49975漏洞复现

★ 6 · 2026-06-11
obrige/http2-bomb

CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console

★ 4 · 2026-06-05
LiaoZiqi-GZFLS/CVE-2026-49975

CVE-2026-49975

★ 3 · 2026-06-10
naheeju/POC-CVE-2026-49975

Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2

★ 3 · 2026-09-16
renzi25031469/CVE-2026-49975-HTTP-2-Bomb

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust se…

★ 2 · 2026-06-08
CVSS 2.0 LOW CWE-284, CWE-434 Published 2026-09-16 PoCs 1 ★ 1 Last push 2026-09-16 (3 weeks, 3 days ago)

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.

Show 1 repositories
d1n3sh-0x3/CVE-2026-92247

Rce In synaptikcms

★ 1 · 2026-09-16
PoCs 1 ★ 0 Last push 2026-09-16 (3 weeks, 3 days ago)

Fetching description from NVD…

Show 1 repositories
fdjy1234/CVE-2022-41404-DoS-Protection

Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection

★ 0 · 2026-09-16
PoCs 1 ★ 0 Last push 2026-09-16 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-65374

CVE-2026-65374 - Draft or TODO

★ 0 · 2026-09-16
CVSS 5.4 MEDIUM CWE-863 Published 2026-09-09 PoCs 1 ★ 5 Last push 2026-09-15 (3 weeks, 4 days ago)

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
MartiSabate/CVE-2023-39141-LFI-enumerator

enumerate files and directories from a remote server

★ 0 · 2026-09-15
PoCs 3 ★ 5 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 3 repositories
686f6c61/POC-AIOWPM-CVE-2026-19949

PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <= 7.109 via regex de replace_table_values. Laborator…

★ 5 · 2026-09-15
katranSefa/CVE-2026-19949
★ 1 · 2026-09-06
HORKimhab/CVE-2026-19949

CVE-2026-19949 - Draft or TODO

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
pavanchow/CVE-2026-33234

SSRF via smtplib raw TCP sockets bypassing HTTP blocklist in AutoGPT SendEmailBlock

★ 0 · 2026-09-15
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
MGTx2/CVE-2026-79294

CVE-2026-79294 — Stored XSS in Moonshot AI Kimi's HTML artifact Preview, delivered through the public Share view, leading to session token exfiltration and dem…

★ 0 · 2026-09-15
PoCs 1 ★ 1 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
Oscar-Collado/langflow-CVE-2026-17633-PoC

PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass research.

★ 1 · 2026-09-15
CVE-2009-2265
MULTI PoC
PoCs 7 ★ 2 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 7 repositories
zaphoxx/zaphoxx-coldfusion

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

★ 2 · 2020-10-02
h3x0v3rl0rd/CVE-2009-2265
★ 1 · 2025-06-05
p1ckzi/CVE-2009-2265

cf8-upload.py | CVE-2009-2265

★ 1 · 2022-06-30
0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265

Adobe ColdFusion 8 - Remote Command Execution (RCE)

★ 1 · 2025-01-07
nika0x38/CVE-2009-2265

A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.

★ 0 · 2025-09-27
matesz44/CVE-2009-2265

posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)

★ 0 · 2026-01-12
hd-exe/CVE-2009-2265-fix

fix for not working exploit script on exploitdb (50057.py)

★ 0 · 2026-09-15
PoCs 4 ★ 2 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 4 repositories
byteReaper77/CVE-2025-8191

A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.

★ 2 · 2025-07-28
mayank-s16/Swagger-HTML-Injection-CVE-2025-8191

XSS Test Swagger 3.14.1 to 3.37.0

★ 0 · 2025-12-08
YanC1e/CVE-2025-8191
★ 0 · 2025-12-30
d154573r-4v3r73d/CVE-2025-8191

Testing for CVE-2025-8191

★ 0 · 2026-09-15
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-15315

CVE-2026-15315, CVE-2026-15316 - Draft or TODO

★ 0 · 2026-09-15
PoCs 3 ★ 86 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 3 repositories
ByteV0rtex/CVE-2026-65343

CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)

★ 86 · 2026-09-04
hidayat-tanjung/CVE-2026-65343-e7eb2ed

CVE-2026-65343: OOB read in AppleKeyStore.kext (_LibSer_SEPControl_Deserialize) copies an ACM buffer to userspace without length validation, letting sandboxed …

★ 2 · 2026-09-15
AmorCool/iOS26.6-CVE-2026-65343

CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)

★ 1 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
FLX-0x00/CVE-2026-59550
★ 0 · 2026-09-15
CVE-2024-36401
HOTMULTI PoC
PoCs 22 ★ 122 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 8 of 22 repositories
whitebear-ch/GeoServerExploit

GeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具

★ 122 · 2025-01-17
Chocapikk/CVE-2024-36401

GeoServer Remote Code Execution

★ 88 · 2025-04-06
Mr-xn/CVE-2024-36401

Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit

★ 56 · 2024-07-06
ahisec/geoserver-

geoserver CVE-2024-36401漏洞利用工具

★ 45 · 2024-07-24
bmth666/GeoServer-Tools-CVE-2024-36401

CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现

★ 42 · 2026-06-08
bigb0x/CVE-2024-36401

POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.

★ 35 · 2024-07-04
Niuwoo/CVE-2024-36401

POC

★ 4 · 2024-07-05
justin-p/geoexplorer

Mass scanner for CVE-2024-36401

★ 4 · 2024-08-27
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
snyi001/CVE-2026-79551-Tenda

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

★ 0 · 2026-09-15
PoCs 1 ★ 10 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
0xCyberstan/CVE-2026-59346-POC

PoC for CVE-2026-59346 - 32-bit integer overflow in VMware's VMXNET3 TSO segmentation path, guest-to-host crash.

★ 10 · 2026-09-15
< Prev Page 31 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.