Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

CVE-2023-1326
MULTI PoC
PoCs 5 ★ 21 Last push 2026-09-12 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 5 repositories
diego-tella/CVE-2023-1326-PoC

A proof of concept for CVE-2023–1326 in apport-cli 2.26.0

★ 21 · 2023-12-06
h3x0v3rl0rd/CVE-2023-1326
★ 1 · 2024-05-04
Pol-Ruiz/CVE-2023-1326

Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326

★ 0 · 2024-01-26
cve-2024/CVE-2023-1326-PoC
★ 0 · 2024-06-14
R3fr4kt/DEVVORTEX

A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enu…

★ 0 · 2026-09-12
PoCs 1 ★ 2 Last push 2026-09-12 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
woaphone/CVE-2021-28664-PoC

A POC of CVE-2021-28664

★ 2 · 2026-09-12
CVE-2022-38181
MULTI PoC
PoCs 6 ★ 7 Last push 2026-09-12 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 6 repositories
Pro-me3us/CVE_2022_38181_Raven

CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)

★ 7 · 2024-12-03
ericpardee/fire-hd-ownership

Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog

★ 6 · 2026-08-24
Pro-me3us/CVE_2022_38181_Gazelle

CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)

★ 4 · 2023-06-29
R0rt1z2/CVE-2022-38181
★ 3 · 2023-07-03
artur9010/amazon-mustang-hack

FireOS 7.3.3.1 temp root by CVE-2022-38181

★ 0 · 2026-09-12
CVE-2026-21858
HOTMULTI PoC
PoCs 17 ★ 303 Last push 2026-09-12 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 17 repositories
Chocapikk/CVE-2026-21858

n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

★ 303 · 2026-03-26
ZeroDayEvil/CVE-2026-21858-n8n-FullChain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…

★ 88 · 2026-09-12
sh4den/CVE-2026-21858

Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.

★ 3 · 2026-07-06
cropnet/Ni8mare

Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0) without perform…

★ 2 · 2026-01-12
sec-dojo-com/CVE-2026-21858
★ 1 · 2026-01-20
EQSTLab/CVE-2026-21858

Ni8mare, n8n RCE

★ 1 · 2026-05-20
0xBlackash/CVE-2026-21858

CVE-2026-21858

★ 1 · 2026-03-05
Fomovet/cve-2026-21858

POC for CVE-2026-21858

★ 1 · 2026-06-21
CVE-2025-68613
HOTMULTI PoC
PoCs 36 ★ 105 Last push 2026-09-12 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 36 repositories
wioui/n8n-CVE-2025-68613-exploit

CVE-2025-68613: n8n RCE vulnerability exploit and documentation

★ 105 · 2025-12-23
ZeroDayEvil/CVE-2026-21858-n8n-FullChain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…

★ 88 · 2026-09-12
TheStingR/CVE-2025-68613-POC

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, f…

★ 29 · 2025-12-26
rxerium/CVE-2025-68613

Detection for CVE-2025-68613

★ 27 · 2025-12-22
LingerANR/n8n-CVE-2025-68613

This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.

★ 7 · 2025-12-26
hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

★ 5 · 2025-12-25
mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613

Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection

★ 2 · 2025-12-25
JohannesLks/CVE-2025-68613-Python-Exploit

Python Exploit for CVE-2025-68613.

★ 1 · 2026-02-14
CVSS 8.7 HIGH CWE-863 Published 2026-09-11 PoCs 1 ★ 6 Last push 2026-09-11 (4 weeks, 1 day ago)

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.

Show 1 repositories
Faceless0x7/CVE-2026-89013

CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.

★ 6 · 2026-09-11
CVSS 7.1 HIGH CWE-178 Published 2026-09-11 PoCs 1 ★ 6 Last push 2026-09-11 (4 weeks, 1 day ago)

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.

Show 1 repositories
Faceless0x7/CVE-2026-89012

CVE-2026-89012 Exploit — SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution and case-sensitive denylist matching.

★ 6 · 2026-09-11
CVSS 8.8 HIGH CWE-787 Published 2026-09-09 PoCs 1 ★ 5 Last push 2026-09-11 (4 weeks, 1 day ago)

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
TheMalwareGuardian/CVE-2022-34302

CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to l…

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
TheMalwareGuardian/CVE-2022-34303

CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corrup…

★ 0 · 2026-09-11
PoCs 1 ★ 1 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
TheMalwareGuardian/CVE-2022-34301

CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load uns…

★ 1 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
lmx-071028/cve-2024-30350-research-notes

Research notes for CVE-2024-30350

★ 0 · 2026-09-11
CVE-2026-20805
MULTI PoC
PoCs 6 ★ 92 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 6 repositories
ZeroDayEvil/CVE-2026-20805-PoC

🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic).

★ 92 · 2026-09-11
fevar54/CVE-2026-20805-POC

PoC de CVE-2026-20805: divulgacion de informacion en Desktop Window Manager (dwm.exe) de Windows.

★ 7 · 2026-01-14
Uzair-Baig0900/CVE-2026-20805-PoC

The PoC of information disclosure in Microsoft Desktop Windows Management.

★ 2 · 2026-01-19
SimoesCTT/-SCTT-2026-33-0002-DWM-Visual-Field-Singularity

### 📡 Theoretical Classification **ID:** SCTT-2026-33-0002 **Researcher:** Americo Simoes (SimoesCTT) **Physics:** Theorem 4.2 - Turbulent Phase Transition…

★ 1 · 2026-01-31
mrk336/Inside-CVE-2026-20805-How-a-Windows-DWM-Flaw-Exposed-Sensitive-Data

CVE‑2026‑20805: A Windows Desktop Window Manager flaw causing local information disclosure. Requires low privileges, no user interaction. Rated CVSS 5.5 (Mediu…

★ 0 · 2026-01-28
SimoesCTT/SCTT-2026-33-0002-DWM-Visual-Field-Singularity

Microsoft just patched CVE-2026-20805 and CVE-2026-20871 in January 2026 to stop "Information Disclosure" and "Use-After-Free" bugs in DWM. They think they've …

★ 0 · 2026-01-31
CVE-2017-7921
HOTMULTI PoC
PoCs 23 ★ 116 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 8 of 23 repositories
chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor

This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.

★ 116 · 2021-01-29
JrDw0/CVE-2017-7921-EXP

Hikvision camera CVE-2017-7921-EXP

★ 102 · 2023-12-04
BurnyMcDull/CVE-2017-7921

海康威视未授权访问检测poc及口令爆破

★ 35 · 2020-11-19
voidsshadows/Hikvision-City-Hunter

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, …

★ 19 · 2025-11-19
MisakaMikato/cve-2017-7921-golang

Hikvision IP camera access bypass exploit, developed by golang.

★ 13 · 2026-03-17
Th3Purge/CVE-2017-7921-Exploit

Exploit for CVE-2017-7921, targeting the improper authentication vulnerability affecting Hikvision camera systems.

★ 9 · 2026-09-11
kooroshsanaei/HikVision-CVE-2017-7921

Test For CVE-2017–7921;

★ 7 · 2024-07-02
alkaid176/CVE-2017-7921

CVE-2017-7921-EXP Hikvision camera

★ 6 · 2022-07-20
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
testardou/CVE-2026-15253

Easy Media Replace <= 0.2.0 - Authenticated (Author+) Stored Cross-Site Scripting

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
testardou/CVE-2026-19794

WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/netty-resolver-dns-check

CVE-2026-45674 / CVE-2026-47691 / CVE-2026-45673: offline checker for DNS cache poisoning in io.netty:netty-resolver-dns - and whether your app actually uses t…

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
PoCs 2 ★ 2 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 2 repositories
TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy

Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept tooling f…

★ 2 · 2026-09-11
TheMalwareGuardian/CVE-2026-79298

CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-734…

★ 2 · 2026-09-11
PoCs 3 ★ 2 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 3 repositories
TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy

Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept tooling f…

★ 2 · 2026-09-11
TheMalwareGuardian/CVE-2026-79298

CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-734…

★ 2 · 2026-09-11
TheMalwareGuardian/CVE-2024-7344

Research on CVE-2024-7344, a Secure Boot bypass affecting Howyar SysReturn through an untrusted EFI payload loading mechanism.

★ 0 · 2026-08-16
CVSS 8.7 HIGH CWE-288 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.

Show 1 repositories
franklincg/secdim-assurance-drift-challenge

SecDim Challenge Builder repro inspired by CVE-2026-88861: AAL1 MFA bypass at privileged credential boundary

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/zotlit-PoC

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

★ 0 · 2026-09-11
CVSS 8.1 HIGH CWE-347 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.

Show 1 repositories
squeeze440/tugtainer-PoC

PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/terrapod-PoC

PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/supernote-obsidian-plugin-PoC

PoC — path traversal via malicious device sync in the Supernote Obsidian plugin (GHSA-3gx3-r874-5pp4, CVE-2026-86999, CVSS 5.6).

★ 0 · 2026-09-11
< Prev Page 34 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.