Fetching description from NVD…
Show 1 repositories
PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11117 results
Fetching description from NVD…
PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).
Fetching description from NVD…
PoC — path traversal via unsanitized LLM-derived domain field in OpenLore (GHSA-5j8x-q7q6-58j5, CVE-2026-87001, CVSS 4.7).
Fetching description from NVD…
PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).
Fetching description from NVD…
PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3).
Fetching description from NVD…
PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).
Fetching description from NVD…
PoC — SSRF via JS-rendering tier bypass of the URL safety filter in crw (GHSA-5jp3-339h-vxqw, CVE-2026-87007, CVSS 7.5).
Fetching description from NVD…
PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).
Fetching description from NVD…
Write-up and proof of concept for CVE-2026-20516: MediaTek Android TV MiracastService confused deputy vulnerability.
Fetching description from NVD…
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocati…
Fetching description from NVD…
CVE-2026-51990 - Draft or TODO
Fetching description from NVD…
Exploit for the CVE-2023-23397
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
Simple PoC in PowerShell for CVE-2023-23397
Proof of Concept for CVE-2023-23397 in Python
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
Fetching description from NVD…
CVE-2025-3248 Langflow RCE Exploit
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
POC of CVE-2025-3248, RCE of LangFlow
Mass-CVE-2025-3248
Langflow Remote Code Execution
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…
Fetching description from NVD…
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
Fetching description from NVD…
Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.
Fetching description from NVD…
CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 Unauthenticated Arbitrary File Upload -> RCE
Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥
Fetching description from NVD…
Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock
Fetching description from NVD…
Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mi…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490
Fetching description from NVD…
Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.
Fetching description from NVD…
The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later incorporates it into …
Fetching description from NVD…
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
Open Web Analytics (OWA) - Unauthenticated Remote Code Execution
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
Open Web Analytics 1.7.3 - Remote Code Execution
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2
Fetching description from NVD…
Might be used to share PoC and findings regarding CVE-2026-73786 in the future
Fetching description from NVD…
PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.