Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11117CVEs tracked
26011PoC repositories
3New in 24h
344PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11117 results

PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/pasteguard-PoC

PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/openlore-PoC

PoC — path traversal via unsanitized LLM-derived domain field in OpenLore (GHSA-5j8x-q7q6-58j5, CVE-2026-87001, CVSS 4.7).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/obsidian-note-toolbar-PoC

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/linux-entra-sso-PoC

PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/gortex-PoC

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/crw-PoC

PoC — SSRF via JS-rendering tier bypass of the URL safety filter in crw (GHSA-5jp3-339h-vxqw, CVE-2026-87007, CVSS 7.5).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/code-graph-rag-PoC

PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (4 weeks, 1 day ago)

Fetching description from NVD…

Show 1 repositories
Dingo97/CVE-2026-20516

Write-up and proof of concept for CVE-2026-20516: MediaTek Android TV MiracastService confused deputy vulnerability.

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
het-P301204/AfterLife

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocati…

★ 0 · 2026-09-11
PoCs 1 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-51990

CVE-2026-51990 - Draft or TODO

★ 1 · 2026-09-11
CVE-2023-23397
HOTMULTI PoC
PoCs 29 ★ 345 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 8 of 29 repositories
sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY

Exploit for the CVE-2023-23397

★ 158 · 2023-03-15
Trackflaw/CVE-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

★ 132 · 2023-03-24
ka7ana/CVE-2023-23397

Simple PoC in PowerShell for CVE-2023-23397

★ 40 · 2023-03-16
tiepologian/CVE-2023-23397

Proof of Concept for CVE-2023-23397 in Python

★ 25 · 2023-03-21
BronzeBee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

★ 14 · 2023-03-22
djackreuter/CVE-2023-23397-PoC
★ 9 · 2023-03-18
CVE-2025-3248
MULTI PoC
PoCs 27 ★ 17 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 8 of 27 repositories
ynsmroztas/CVE-2025-3248-Langflow-RCE

CVE-2025-3248 Langflow RCE Exploit

★ 17 · 2025-06-17
xuemian168/CVE-2025-3248

A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。

★ 11 · 2025-04-10
verylazytech/CVE-2025-3248
★ 10 · 2025-04-16
0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

★ 7 · 2025-06-23
PuddinCat/CVE-2025-3248-POC

POC of CVE-2025-3248, RCE of LangFlow

★ 3 · 2025-04-10
dennisec/Mass-CVE-2025-3248

Mass-CVE-2025-3248

★ 3 · 2025-06-23
EQSTLab/CVE-2025-3248

Langflow Remote Code Execution

★ 3 · 2025-09-17
drackyjr/cve-2025-3248-exploit

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…

★ 3 · 2025-11-21
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
kyaw-tun/blue-team-capstone

CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.

★ 0 · 2026-09-11
PoCs 1 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
LindHunt/CVE-2026-26211

Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

★ 1 · 2026-09-11
PoCs 2 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 2 repositories
JohenLastGen-JLG/CVE-2026-18351

CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 Unauthenticated Arbitrary File Upload -> RCE

★ 1 · 2026-09-11
ChiefYoru/Exploit-CVE-2026-18351

Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
abhinavagarwal07/scadapack-secure-lock-poc

Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
abdul-kalam2000/retbleed-speculative-execution-poc

Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mi…

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 1 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
hakaioffsec/CVE-2026-63642
★ 1 · 2026-09-10
PoCs 2 ★ 17 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 2 repositories
TarPeg007/CVE-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

★ 17 · 2026-09-02
BishopFox/CVE-2026-19490-check

Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490

★ 1 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
YonLiud/CVE-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later incorporates it into …

★ 0 · 2026-09-10
CVE-2022-24637
MULTI PoC
PoCs 7 ★ 5 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
Lay0us/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3

★ 5 · 2022-08-30
hupe1980/CVE-2022-24637

Open Web Analytics (OWA) - Unauthenticated Remote Code Execution

★ 5 · 2022-10-12
icebreack/CVE-2022-24637

FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)

★ 4 · 2022-11-15
Pflegusch/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution

★ 4 · 2023-04-08
0xM4hm0ud/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

★ 3 · 2023-03-26
0xRyuk/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

★ 1 · 2023-08-22
PrinceAikinsBaidoo/CVE-2022-24637
★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
promasu/CVE-2026-73786

Might be used to share PoC and findings regarding CVE-2026-73786 in the future

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/inference-gateway-PoC

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

★ 0 · 2026-09-10
< Prev Page 35 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.