Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-94503
CVE-2026-85097
CVE-2026-37107
3 contacts in last 24h
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
11117 results
PoCs 5
★ 21
Last push 2026-09-12 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 5 repositories
R3fr4kt/DEVVORTEX
A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enu…
★ 0 · 2026-09-12
PoCs 1
★ 2
Last push 2026-09-12 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 6
★ 7
Last push 2026-09-12 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 6 repositories
PoCs 17
★ 303
Last push 2026-09-12 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 17 repositories
ZeroDayEvil/CVE-2026-21858-n8n-FullChain
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…
★ 88 · 2026-09-12
sh4den/CVE-2026-21858
Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.
★ 3 · 2026-07-06
cropnet/Ni8mare
Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0) without perform…
★ 2 · 2026-01-12
PoCs 36
★ 105
Last push 2026-09-12 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 36 repositories
ZeroDayEvil/CVE-2026-21858-n8n-FullChain
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chai…
★ 88 · 2026-09-12
TheStingR/CVE-2025-68613-POC
Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, f…
★ 29 · 2025-12-26
LingerANR/n8n-CVE-2025-68613
This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.
★ 7 · 2025-12-26
CVSS 8.7 HIGH
CWE-863
Published 2026-09-11
PoCs 1
★ 6
Last push 2026-09-11 (4 weeks, 1 day ago)
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining access to application logs, uploaded business documents, database backups containing password hashes, and files belonging to other multicompany entities.
Show 1 repositories
Faceless0x7/CVE-2026-89013
CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.
★ 6 · 2026-09-11
CVSS 7.1 HIGH
CWE-178
Published 2026-09-11
PoCs 1
★ 6
Last push 2026-09-11 (4 weeks, 1 day ago)
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
Show 1 repositories
Faceless0x7/CVE-2026-89012
CVE-2026-89012 Exploit — SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution and case-sensitive denylist matching.
★ 6 · 2026-09-11
CVSS 8.8 HIGH
CWE-787
Published 2026-09-09
PoCs 1
★ 5
Last push 2026-09-11 (4 weeks, 1 day ago)
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
TheMalwareGuardian/CVE-2022-34302
CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to l…
★ 0 · 2026-09-11
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
TheMalwareGuardian/CVE-2022-34303
CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corrup…
★ 0 · 2026-09-11
PoCs 1
★ 1
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
TheMalwareGuardian/CVE-2022-34301
CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load uns…
★ 1 · 2026-09-11
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 6
★ 92
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 6 repositories
ZeroDayEvil/CVE-2026-20805-PoC
🛡️ Official AI Security Tool module for CVE-2026-20805 (Desktop Window Manager / dwm.exe Information Disclosure & Memory Leak Diagnostic).
★ 92 · 2026-09-11
PoCs 23
★ 116
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 8 of 23 repositories
voidsshadows/Hikvision-City-Hunter
This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, …
★ 19 · 2025-11-19
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
xiaoqiMikko/netty-resolver-dns-check
CVE-2026-45674 / CVE-2026-47691 / CVE-2026-45673: offline checker for DNS cache poisoning in io.netty:netty-resolver-dns - and whether your app actually uses t…
★ 0 · 2026-09-11
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 2
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 2 repositories
TheMalwareGuardian/CVE-2026-79298
CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-734…
★ 2 · 2026-09-11
PoCs 3
★ 2
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 3 repositories
TheMalwareGuardian/CVE-2026-79298
CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-734…
★ 2 · 2026-09-11
CVSS 8.7 HIGH
CWE-288
Published 2026-09-10
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_backend/utils/hono_middleware.ts) accepts the JWT without validating its assurance level, and the direct RBAC path (checkPermission()/checkPermissionPg() in supabase/functions/_backend/utils/rbac.ts calling public.rbac_check_permission_direct()) authorizes by user ID without passing or checking the session aal, unlike the public.verify_mfa() control which correctly requires aal2. An attacker who knows only the victim's password can therefore authenticate, mint a persistent app-scoped app_admin API key that remains valid after the aal1 session is logged out, and perform privileged operations such as modifying production OTA channel configurations (validated by changing a public production channel from bundle 1.0.0 to 1.0.1), defeating the protection provided by MFA.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
squeeze440/zotlit-PoC
PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).
★ 0 · 2026-09-11
CVSS 8.1 HIGH
CWE-347
Published 2026-09-30
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
Show 1 repositories
squeeze440/tugtainer-PoC
PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1).
★ 0 · 2026-09-11
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
squeeze440/terrapod-PoC
PoC — missing authorization on the platform-wide GPG trust-anchor store in Terrapod (GHSA-6qrc-597p-mrp9, CVE-2026-87006, CVSS 6.5).
★ 0 · 2026-09-11
PoCs 1
★ 0
Last push 2026-09-11 (4 weeks, 1 day ago)
Fetching description from NVD…
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.