Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
3 contacts in last 24h
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
11117 results
PoCs 46
★ 11
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 46 repositories
Dh4nuJ4/SimpleCTF-UpdatedExploit
This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= …
★ 6 · 2024-06-20
JagdeepSinghCeh/cms-made-simple-python3
Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved…
★ 2 · 2025-11-15
PoCs 19
★ 183
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 19 repositories
so1icitx/CVE-2024-25600
Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.
★ 13 · 2026-09-13
PoCs 42
★ 53
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 of 42 repositories
CVSS 4.8 MEDIUM
CWE-193
Published 2026-09-13
PoCs 1
★ 0
Last push 2026-09-13 (3 weeks, 6 days ago)
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Show 1 repositories
PoCs 6
★ 311
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 6 repositories
farazsth98/chronomaly
Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.
★ 311 · 2026-01-05
farazsth98/poc-CVE-2025-38352
This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin menti…
★ 117 · 2026-01-05
AnalyticETH/chronomaly-webos
CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibl…
★ 17 · 2026-06-01
PoCs 1
★ 1
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
ozcanpng/CVE-2026-76071
Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler
★ 1 · 2026-09-13
PoCs 1
★ 1
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
ozcanpng/CVE-2026-76070
Original research and PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi
★ 1 · 2026-09-13
PoCs 1
★ 0
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 1 repositories
BL0odz/JFrog_CVE-2026-65615-ByGLM
JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)
★ 0 · 2026-09-13
PoCs 2
★ 0
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 2 repositories
PoCs 8
★ 54
Last push 2026-09-13 (3 weeks, 6 days ago)
Fetching description from NVD…
Show 8 repositories
kitctf/nginxpwn
Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow
★ 54 · 2016-03-23
PoCs 2
★ 0
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 2 repositories
0cqb/CVE-2026-24332
Unpatched Discord privacy leak allowing presence inference while Invisible.
★ 0 · 2026-09-13
PoCs 1
★ 0
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 8
★ 6
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 8 repositories
uLl0a/CVE-2026-50751
Bypass de autenticación por certificado en la VPN Remote-Access de Check Point (IKEv1).
★ 1 · 2026-09-13
e4zyy/Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
★ 0 · 2026-08-28
PoCs 1
★ 1
Last push 2026-09-13 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
mbeweoo/flash-exploit-defense-system
Comprehensive multi-layer defense system against Adobe Flash CVE exploits (CVE-2012-0754, CVE-2015-xxxx, CVE-2016-xxxx, CVE-2018-xxxx) with browser, mobile, se…
★ 0 · 2026-09-12
PoCs 1
★ 240
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 4
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 22
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 2 repositories
PoCs 1
★ 1
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 1 repositories
pervinzahidli/CVE-2026-77771
In the miniOrange 2FA WordPress plugin (versions before 6.3.1 and 19.3), the two-factor authentication (2FA) attempt limit is flawed.
★ 0 · 2026-09-12
PoCs 2
★ 0
Last push 2026-09-12 (4 weeks ago)
Fetching description from NVD…
Show 2 repositories
CVSS 6.9 MEDIUM
CWE-476
Published 2026-09-09
PoCs 1
★ 0
Last push 2026-09-12 (4 weeks, 1 day ago)
mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.