Fetching description from NVD…
Show 1 repositories
Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283), trades cryp…
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283), trades cryp…
Fetching description from NVD…
## What is CVE-2026-24733? Apache Tomcat incorrectly handled an HTTP/0.9-style `HEAD` request under certain security-constraint configurations.
Fetching description from NVD…
CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882
Proof-of-Concept exploits for CVE-2017-11882
CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
PoC for CVE-2018-0802 And CVE-2017-11882
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-did…
CVE-2017-11882 exploitation
CVE-2017-11882 File Generator PoC
Fetching description from NVD…
🧪 Measures memory-poisoning / prompt-injection deterministically — anchored to CVE-2026-24301 (CoSnitch), Inspect scorer, signed receipts. Measurement, not cer…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
CVE-2026-52910 kernel crash PoC. screen goes off.
POC of cve-2026-52910
Fetching description from NVD…
Fetching description from NVD…
Proof of Concept for CVE-2026-61797, a time-based blind SQL Injection vulnerability affecting the GLPI PDF plugin.
Fetching description from NVD…
OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem
Fetching description from NVD…
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)
CVE-2026-60004
CVE-2026-60004
Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account
CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection
Gitea diffpatch RCE
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1
Fetching description from NVD…
CVE-2021-4034 1day
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
Proof of concept for pwnkit vulnerability
Python exploit code for CVE-2021-4034 (pwnkit)
PoC for CVE-2021-4034 dubbed pwnkit
Proof of Concept (PoC) CVE-2021-4034
CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation
Fetching description from NVD…
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a page-cache page by 24 bytes. PoC plus an unprivileged…
Fetching description from NVD…
CVE-2026-47884:覆盖 15 条 Spring / Tomcat 官方安全公告,8 条被 NVD 报成 CRITICAL 9.x 而厂商官方评 LOW/MEDIUM,另 7 条两边一致 —— 差别只在厂商有没有自己提交 CVSS。工具告诉你中了哪几条、官方评多少分、是否真满足触发条件,以及官方叫你升的版本…
Fetching description from NVD…
Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery
Fetching description from NVD…
A root exploit for CVE-2022-0847 (Dirty Pipe)
A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…
CVE-2022-0847
Container Excape PoC for CVE-2022-0847 "DirtyPipe"
Bash script to check for CVE-2022-0847 "Dirty Pipe"
Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.
CVE-2022-0847
S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.
Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)
Fetching description from NVD…
Published vulnerability reports by JunZ-Leo; credited reporter for CVE-2025-4028 and CVE-2025-4030.
Fetching description from NVD…
Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center.
CVE-2026-20079
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Public release of CVE-2026-87492 🥷
Fetching description from NVD…
Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, …
C++ Windows research tool for studying the BdApiUtil64.sys vulnerable driver and CVE-2024-51324
Fetching description from NVD…
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
Fetching description from NVD…
Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2
Fetching description from NVD…
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4
Exploit for CVE-2024-27198 - TeamCity Server
CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.