Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
Freire007-byte/sentric-core

Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283), trades cryp…

★ 0 · 2026-09-15
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 4 days ago)

Fetching description from NVD…

Show 1 repositories
Darabium/CVE-2026-24733

## What is CVE-2026-24733? Apache Tomcat incorrectly handled an HTTP/0.9-style `HEAD` request under certain security-constraint configurations.

★ 0 · 2026-09-15
CVE-2017-11882
HOTMULTI PoC
PoCs 33 ★ 534 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 33 repositories
Ridter/CVE-2017-11882

CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882

★ 534 · 2017-11-29
embedi/CVE-2017-11882

Proof-of-Concept exploits for CVE-2017-11882

★ 494 · 2017-11-29
rip1s/CVE-2017-11882

CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.

★ 330 · 2017-12-06
rxwx/CVE-2018-0802

PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)

★ 270 · 2018-02-28
Ridter/RTF_11882_0802

PoC for CVE-2018-0802 And CVE-2017-11882

★ 166 · 2018-01-12
0x09AL/CVE-2017-11882-metasploit

This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-did…

★ 98 · 2017-11-21
starnightcyber/CVE-2017-11882

CVE-2017-11882 exploitation

★ 44 · 2017-11-28
BlackMathIT/2017-11882_Generator

CVE-2017-11882 File Generator PoC

★ 34 · 2017-11-22
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
CSOAI-ORG/memory-poisoning-axis

🧪 Measures memory-poisoning / prompt-injection deterministically — anchored to CVE-2026-24301 (CoSnitch), Inspect scorer, signed receipts. Measurement, not cer…

★ 0 · 2026-09-15
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
isaca0315/CVE-2026-44351-poc
★ 0 · 2026-09-15
PoCs 2 ★ 11 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 2 repositories
Dere3046/ScreenOff

CVE-2026-52910 kernel crash PoC. screen goes off.

★ 11 · 2026-07-21
yolkfull/cve-2026-52910-poc

POC of cve-2026-52910

★ 1 · 2026-09-15
PoCs 1 ★ 0 Last push 2026-09-15 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
0xf9b6a41ec/CVE-2026-69328
★ 0 · 2026-09-15
PoCs 1 ★ 1 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
itres-labs/CVE-2026-61797

Proof of Concept for CVE-2026-61797, a time-based blind SQL Injection vulnerability affecting the GLPI PDF plugin.

★ 1 · 2026-09-14
PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
uziii2208/CVE-2026-86259

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

★ 0 · 2026-09-14
CVE-2026-88899
CRITICAL
CVSS 9.3 CRITICAL CWE-73 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 5 days ago)

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

Show 1 repositories
uziii2208/CVE-2026-88899

Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

★ 0 · 2026-09-14
CVE-2026-60004
MULTI PoC
PoCs 11 ★ 16 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 11 repositories
imbas007/CVE-2026-60004-POC

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

★ 16 · 2026-08-03
HORKimhab/CVE-2026-60004

CVE-2026-60004

★ 5 · 2026-07-29
0xBlackash/CVE-2026-60004

CVE-2026-60004

★ 5 · 2026-07-30
HackSpeak/CVE-2026-60004

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

★ 2 · 2026-08-04
gagaltotal/CVE-2026-60004-poc-gitea

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

★ 2 · 2026-08-08
EQSTLab/CVE-2026-60004

Gitea diffpatch RCE

★ 1 · 2026-08-19
yym8538/CVE-2026-60004
★ 1 · 2026-08-21
shinthink/CVE-2026-60004

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

★ 0 · 2026-08-03
CVE-2021-4034
HOTMULTI PoC
PoCs 182 ★ 2044 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 182 repositories
berdav/CVE-2021-4034

CVE-2021-4034 1day

★ 2044 · 2022-06-08
ly4k/PwnKit

Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation

★ 1331 · 2022-06-21
arthepsy/CVE-2021-4034

PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)

★ 1165 · 2023-05-04
PwnFunction/CVE-2021-4034

Proof of concept for pwnkit vulnerability

★ 352 · 2023-01-12
joeammond/CVE-2021-4034

Python exploit code for CVE-2021-4034 (pwnkit)

★ 180 · 2022-01-28
dzonerzy/poc-cve-2021-4034

PoC for CVE-2021-4034 dubbed pwnkit

★ 114 · 2022-01-27
luijait/PwnKit-Exploit

Proof of Concept (PoC) CVE-2021-4034

★ 98 · 2022-02-07
Rvn0xsy/CVE-2021-4034

CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation

★ 96 · 2022-01-28
PoCs 1 ★ 17 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
0xCyberstan/CVE-2026-31694-POC

Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a page-cache page by 24 bytes. PoC plus an unprivileged…

★ 17 · 2026-09-14
PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/spring-cvss-check

CVE-2026-47884:覆盖 15 条 Spring / Tomcat 官方安全公告,8 条被 NVD 报成 CRITICAL 9.x 而厂商官方评 LOW/MEDIUM,另 7 条两边一致 —— 差别只在厂商有没有自己提交 CVSS。工具告诉你中了哪几条、官方评多少分、是否真满足触发条件,以及官方叫你升的版本…

★ 0 · 2026-09-14
PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 1 repositories
testardou/CVE-2026-65540

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

★ 0 · 2026-09-14
CVE-2022-0847
HOTMULTI PoC
PoCs 109 ★ 1133 Last push 2026-09-14 (3 weeks, 5 days ago)

Fetching description from NVD…

Show 8 of 109 repositories
Arinerron/CVE-2022-0847-DirtyPipe-Exploit

A root exploit for CVE-2022-0847 (Dirty Pipe)

★ 1133 · 2022-03-08
AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits

A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.

★ 735 · 2023-05-20
r1is/CVE-2022-0847

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…

★ 282 · 2023-02-02
Al1ex/CVE-2022-0847

CVE-2022-0847

★ 91 · 2022-03-09
DataDog/dirtypipe-container-breakout-poc

Container Excape PoC for CVE-2022-0847 "DirtyPipe"

★ 77 · 2022-04-20
basharkey/CVE-2022-0847-dirty-pipe-checker

Bash script to check for CVE-2022-0847 "Dirty Pipe"

★ 72 · 2023-06-14
ZZ-SOCMAP/CVE-2022-0847

Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.

★ 58 · 2022-03-08
bbaranoff/CVE-2022-0847

CVE-2022-0847

★ 50 · 2022-03-07
CVSS 6.0 MEDIUM CWE-476 Published 2026-09-13 PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 6 days ago)

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.

Show 1 repositories
HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber

Standalone PoC for CVE-2026-90782: status-clobbering NULL dereference in S2OPC alloc_notification_message_items() (DataChange fails, Event succeeds)

★ 0 · 2026-09-14
PoCs 1 ★ 0 Last push 2026-09-14 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
JunZ-Leo/CVE

Published vulnerability reports by JunZ-Leo; credited reporter for CVE-2025-4028 and CVE-2025-4030.

★ 0 · 2026-09-14
PoCs 3 ★ 6 Last push 2026-09-14 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 3 repositories
CyberAuth/CVE-2026-20079

Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center.

★ 6 · 2026-08-24
0xBlackash/CVE-2026-20079

CVE-2026-20079

★ 0 · 2026-03-28
CVE-2026-87492
CRITICAL
CVSS 9.6 CRITICAL CWE-863 Published 2026-09-09 PoCs 1 ★ 4 Last push 2026-09-13 (3 weeks, 6 days ago)

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Show 1 repositories
valencenavy/IsolatedAnarchy-Public

Public release of CVE-2026-87492 🥷

★ 4 · 2026-09-13
PoCs 2 ★ 1 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 2 repositories
devianntsec/CVE-2024-51324

Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, …

★ 1 · 2026-04-27
uLl0a/bdapiutil-bydov

C++ Windows research tool for studying the BdApiUtil64.sys vulnerable driver and CVE-2024-51324

★ 0 · 2026-09-13
PoCs 1 ★ 7 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
erberkan/CVE-2026-42536-PoC

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

★ 7 · 2026-09-13
PoCs 1 ★ 1 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
eorll-lgtm/poc-CVE-2026-23489

Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2

★ 1 · 2026-09-13
CVE-2024-27198
HOTMULTI PoC
PoCs 19 ★ 154 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 19 repositories
W01fh4cker/CVE-2024-27198-RCE

CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4

★ 154 · 2024-03-11
yoryio/CVE-2024-27198

Exploit for CVE-2024-27198 - TeamCity Server

★ 37 · 2024-12-19
Stuub/RCity-CVE-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

★ 35 · 2024-07-19
Chocapikk/CVE-2024-27198

Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4

★ 34 · 2024-03-05
passwa11/CVE-2024-27198-RCE
★ 3 · 2024-03-08
geniuszly/CVE-2024-27198

is a PoC tool that targets a vulnerability in the TeamCity server (CVE-2024-27198)

★ 3 · 2024-10-09
ptd200110/CVE-2024-27198-SOC-Lab
★ 2 · 2026-06-19
CharonDefalt/CVE-2024-27198-RCE
★ 1 · 2024-03-09
< Prev Page 32 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.