Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVE-2019-9053
MULTI PoC
PoCs 46 ★ 11 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 46 repositories
4nner/CVE-2019-9053

CVE-2019-9053 Exploit for Python 3

★ 11 · 2023-05-09
Mahamedm/CVE-2019-9053-Exploit-Python-3

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

★ 8 · 2025-02-10
Dh4nuJ4/SimpleCTF-UpdatedExploit

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= …

★ 6 · 2024-06-20
h3x0v3rl0rd/CVE-2019-9053
★ 3 · 2025-06-05
JagdeepSinghCeh/cms-made-simple-python3

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved…

★ 2 · 2025-11-15
d3athcod3/46635.py_CVE-2019-9053

This is modified code of 46635 exploit from python2 to python3.

★ 1 · 2021-05-14
CVE-2024-25600
HOTMULTI PoC
PoCs 19 ★ 183 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 19 repositories
Chocapikk/CVE-2024-25600

Unauthenticated Remote Code Execution – Bricks <= 1.9.6

★ 183 · 2024-02-25
Christbowel/CVE-2024-25600_Nuclei-Template

Nuclei template and information about the POC for CVE-2024-25600

★ 31 · 2024-02-21
so1icitx/CVE-2024-25600

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

★ 13 · 2026-09-13
Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for unauthenticate…

★ 8 · 2024-02-22
X-Projetion/WORDPRESS-CVE-2024-25600-EXPLOIT-RCE

WORDPRESS-CVE-2024-25600-EXPLOIT-RCE - WordPress Bricks Builder Remote Code Execution (RCE)

★ 1 · 2024-04-20
estebanzarate/CVE-2024-25600-WordPress-Bricks-Builder-RCE-PoC

Unauthenticated remote code execution vulnerability in WordPress Bricks Builder <= 1.9.6. The template render endpoint accepts PHP code without authentication,…

★ 1 · 2026-02-19
CerberusMrXi/WP-Bricks-Exploit-CVE-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse shells, file u…

★ 1 · 2026-07-16
svchostmm/CVE-2024-25600-mass
★ 0 · 2024-05-05
CVE-2025-48384
MULTI PoC
PoCs 42 ★ 53 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 of 42 repositories
acheong08/CVE-2025-48384

Breaking git with a carriage return and cloning RCE

★ 53 · 2025-07-08
liamg/CVE-2025-48384

PoC for CVE-2025-48384

★ 20 · 2025-07-09
vinieger/vinieger-CVE-2025-48384-Dockerfile

PoC dockerfile image for CVE-2025-48384

★ 1 · 2025-07-11
IK-20211125/CVE-2025-48384

CVE-2025-48384 PoC

★ 1 · 2025-07-21
zr0n/CVE-2025-48384-sub
★ 1 · 2025-12-04
zr0n/CVE-2025-48384-main

A proof of concept of remote code execution

★ 1 · 2025-12-04
fishyyh/CVE-2025-48384

for CVE-2025-48384 test

★ 0 · 2025-07-09
CVSS 4.8 MEDIUM CWE-193 Published 2026-09-13 PoCs 1 ★ 0 Last push 2026-09-13 (3 weeks, 6 days ago)

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

Show 1 repositories
HarshRajSinghania/CVE-2026-90781-alsa-lib-oob

Standalone reproducer for CVE-2026-90781: 1-byte OOB write in alsa-lib __snd_ctl_ascii_elem_id_parse() name= parsing (quoted and unquoted)

★ 0 · 2026-09-13
CVE-2025-38352
HOTMULTI PoC
PoCs 6 ★ 311 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 6 repositories
farazsth98/chronomaly

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

★ 311 · 2026-01-05
farazsth98/poc-CVE-2025-38352

This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin menti…

★ 117 · 2026-01-05
AnalyticETH/chronomaly-webos

CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibl…

★ 17 · 2026-06-01
jordelmir/Elysium-Vanguard-Sentinel-Audit

The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.

★ 2 · 2026-02-24
Crime2/poc-CVE-2025-38352
★ 0 · 2026-01-08
longwasu/CVE-2025-38352-PoC

PoC and GDB script assists in triggering CVE-2025-38352

★ 0 · 2026-09-13
PoCs 1 ★ 1 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
ozcanpng/CVE-2026-76071

Original research and PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

★ 1 · 2026-09-13
PoCs 1 ★ 1 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
ozcanpng/CVE-2026-76070

Original research and PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi

★ 1 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 1 repositories
BL0odz/JFrog_CVE-2026-65615-ByGLM

JFrog Artifactory 预认证全链 RCE 复现项目(CVE-2026-42018 / CVE-2026-65616 / CVE-2026-65615):完整攻击链报告、7.146.7 Docker 复现交付物(EXP / 部署 / 基线验证 / payload 样本 / 恢复工具)

★ 0 · 2026-09-13
PoCs 2 ★ 0 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 2 repositories
oscar-mine/CVE-2026-23980-Exploit

Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass

★ 0 · 2026-04-12
hyphenTBG/CVE-2026-23980

Modified exploit of CVE-2026-23980

★ 0 · 2026-09-13
CVE-2013-2028
MULTI PoC
PoCs 8 ★ 54 Last push 2026-09-13 (3 weeks, 6 days ago)

Fetching description from NVD…

Show 8 repositories
kitctf/nginxpwn

Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow

★ 54 · 2016-03-23
danghvu/nginx-1.4.0

For the analysis of CVE-2013-2028

★ 30 · 2018-06-07
m4drat/CVE-2013-2028-Exploit

CVE-2013-2028 python exploit

★ 19 · 2020-06-27
tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC

this is not stable

★ 2 · 2019-08-03
jptr218/nginxhack

A CVE-2013-2028 implementation

★ 1 · 2021-07-27
Sunqiz/CVE-2013-2028-reproduction

CVE-2013-2028复现

★ 0 · 2022-08-15
xiw1ll/CVE-2013-2028_Checker

Tool for checking Nginx CVE-2013-2028

★ 0 · 2024-07-23
vanivamshi/CVE-2013-2028-Exploit
★ 0 · 2026-09-13
PoCs 2 ★ 0 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 2 repositories
0cqb/CVE-2026-24332

Unpatched Discord privacy leak allowing presence inference while Invisible.

★ 0 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
HarshRajSinghania/cotonti-commentswidget-poc

Safe local proof of concept for the Cotonti CommentsWidget PHP object injection vulnerability (CAN-2026-2035973 / CVE-2026-71294).

★ 0 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
htrxuan/hdwebmobile-photo-video-reviews

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

★ 0 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
htrxuan/hdwebmobile-formula-pricing

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

★ 0 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
htrxuan/hdwebmobile-booking-appointments

Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.

★ 0 · 2026-09-13
CVE-2026-50751
MULTI PoC
PoCs 8 ★ 6 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 8 repositories
WadesWeaponShed/CVE-2026-50751-Mitigation-Scripts

Mitigation scripts for CVE-2026-50751

★ 1 · 2026-06-13
0xBlackash/CVE-2026-50751

CVE-2026-50751

★ 1 · 2026-06-08
fevar54/CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit

PoC de CVE-2026-50751: bypass de autenticacion IKEv1 en Check Point Remote/Mobile Access.

★ 1 · 2026-06-10
WadesWeaponShed/CheckPoint-CVE-Webscanner

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using Check Point…

★ 1 · 2026-09-11
uLl0a/CVE-2026-50751

Bypass de autenticación por certificado en la VPN Remote-Access de Check Point (IKEv1).

★ 1 · 2026-09-13
fernstedt/CVE-2026-50751

CVE-2026-50751 Check Point IKEv1 vulnerability scanner

★ 0 · 2026-06-10
e4zyy/Project-CVE-2026-50751

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.

★ 0 · 2026-08-28
PoCs 1 ★ 1 Last push 2026-09-13 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
hanzzly/CVE-2024-2044
★ 1 · 2026-09-13
PoCs 1 ★ 0 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
mbeweoo/flash-exploit-defense-system

Comprehensive multi-layer defense system against Adobe Flash CVE exploits (CVE-2012-0754, CVE-2015-xxxx, CVE-2016-xxxx, CVE-2018-xxxx) with browser, mobile, se…

★ 0 · 2026-09-12
PoCs 1 ★ 240 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
garatc/BitUnlocker

Downgrade attack for CVE-2025-48804

★ 240 · 2026-09-12
PoCs 1 ★ 4 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
Xernary/CVE-2026-82539

Security advisory for TOTOLINK a720r buffer overflow vulnerability

★ 4 · 2026-09-12
PoCs 2 ★ 22 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 2 repositories
Daniel224455/katana

Let's hijack our bootchain - CVE-2021-30327

★ 22 · 2026-09-12
Daniel224455/echidna

Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327

★ 6 · 2026-08-25
PoCs 1 ★ 1 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
Wayang1337/CVE-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

★ 1 · 2026-09-12
PoCs 1 ★ 0 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 1 repositories
pervinzahidli/CVE-2026-77771

In the miniOrange 2FA WordPress plugin (versions before 6.3.1 and 19.3), the two-factor authentication (2FA) attempt limit is flawed.

★ 0 · 2026-09-12
PoCs 2 ★ 0 Last push 2026-09-12 (4 weeks ago)

Fetching description from NVD…

Show 2 repositories
CVSS 6.9 MEDIUM CWE-476 Published 2026-09-09 PoCs 1 ★ 0 Last push 2026-09-12 (4 weeks, 1 day ago)

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.

Show 1 repositories
HarshRajSinghania/cve-2026-86547-mrubyc-op-enter

Standalone proof of concept for CVE-2026-86547, a NULL pointer dereference in mrubyc op_enter() through 4.0.0.

★ 0 · 2026-09-12
< Prev Page 33 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.