Fetching description from NVD…
Show 1 repositories
Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe
Fetching description from NVD…
WordPress - Authenticated XXE (CVE-2021-29447)
A proof of concept exploit for a wordpress 5.6 media library vulnerability
WordPress XXE vulnerability
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
Wordpress XXE injection 구축 자동화 및 PoC
Arbitrary file read controller based on CVE-2021-29447
A Golang program to automate the execution of CVE-2021-29447
Fetching description from NVD…
CVE-2026-22686-RemoteCodeExecution-RCE-PoC
Fetching description from NVD…
research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607
Fetching description from NVD…
CVE-2026-65330 PoC — setxattr PAC bypass via fixed #0x307a diversifier (iOS 26.6 / 23G71)
My first CVE
Fetching description from NVD…
WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read
Fetching description from NVD…
Docmost < 0.22.0 - Arbitrary File Read
Fetching description from NVD…
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
HTTP/2 Bomb
PoC de CVE-2026-49975 (HTTP/2 Bomb): DoS remoto contra servidores web con HTTP/2 por defecto.
CVE-2026-49975漏洞复现
CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console
CVE-2026-49975
Security research PoC for CVE-2026-49975: HTTP/2 HPACK compression bomb + flow-control hold DoS in Apache mod_http2
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to exhaust se…
A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin File Manager. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 1.3.5 is able to mitigate this issue. It is suggested to upgrade the affected component.
Rce In synaptikcms
Fetching description from NVD…
Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection
Fetching description from NVD…
CVE-2026-65374 - Draft or TODO
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Fetching description from NVD…
enumerate files and directories from a remote server
Fetching description from NVD…
PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <= 7.109 via regex de replace_table_values. Laborator…
CVE-2026-19949 - Draft or TODO
Fetching description from NVD…
SSRF via smtplib raw TCP sockets bypassing HTTP blocklist in AutoGPT SendEmailBlock
Fetching description from NVD…
CVE-2026-79294 — Stored XSS in Moonshot AI Kimi's HTML artifact Preview, delivered through the public Share view, leading to session token exfiltration and dem…
Fetching description from NVD…
PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass research.
Fetching description from NVD…
coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/
cf8-upload.py | CVE-2009-2265
Adobe ColdFusion 8 - Remote Command Execution (RCE)
A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.
posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)
fix for not working exploit script on exploitdb (50057.py)
Fetching description from NVD…
A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.
XSS Test Swagger 3.14.1 to 3.37.0
Testing for CVE-2025-8191
Fetching description from NVD…
CVE-2026-15315, CVE-2026-15316 - Draft or TODO
Fetching description from NVD…
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
CVE-2026-65343: OOB read in AppleKeyStore.kext (_LibSer_SEPControl_Deserialize) copies an ACM buffer to userspace without length validation, letting sandboxed …
CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)
Fetching description from NVD…
Fetching description from NVD…
GeoServer(CVE-2024-36401/CVE-2024-36404)漏洞利用工具
GeoServer Remote Code Execution
Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit
geoserver CVE-2024-36401漏洞利用工具
CVE-2024-36401 图形化利用工具,支持各个JDK版本利用以及回显、内存马实现
POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.
Mass scanner for CVE-2024-36401
Fetching description from NVD…
Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.
Fetching description from NVD…
PoC for CVE-2026-59346 - 32-bit integer overflow in VMware's VMXNET3 TSO segmentation path, guest-to-host crash.
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.