Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
14New in 24h
369PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
het-P301204/AfterLife

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocati…

★ 0 · 2026-09-11
PoCs 1 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-51990

CVE-2026-51990 - Draft or TODO

★ 1 · 2026-09-11
CVE-2023-23397
HOTMULTI PoC
PoCs 29 ★ 345 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 8 of 29 repositories
sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY

Exploit for the CVE-2023-23397

★ 158 · 2023-03-15
Trackflaw/CVE-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

★ 132 · 2023-03-24
ka7ana/CVE-2023-23397

Simple PoC in PowerShell for CVE-2023-23397

★ 40 · 2023-03-16
tiepologian/CVE-2023-23397

Proof of Concept for CVE-2023-23397 in Python

★ 25 · 2023-03-21
BronzeBee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

★ 14 · 2023-03-22
djackreuter/CVE-2023-23397-PoC
★ 9 · 2023-03-18
CVE-2025-3248
MULTI PoC
PoCs 27 ★ 17 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 8 of 27 repositories
ynsmroztas/CVE-2025-3248-Langflow-RCE

CVE-2025-3248 Langflow RCE Exploit

★ 17 · 2025-06-17
xuemian168/CVE-2025-3248

A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。

★ 11 · 2025-04-10
verylazytech/CVE-2025-3248
★ 10 · 2025-04-16
0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

★ 7 · 2025-06-23
PuddinCat/CVE-2025-3248-POC

POC of CVE-2025-3248, RCE of LangFlow

★ 3 · 2025-04-10
dennisec/Mass-CVE-2025-3248

Mass-CVE-2025-3248

★ 3 · 2025-06-23
EQSTLab/CVE-2025-3248

Langflow Remote Code Execution

★ 3 · 2025-09-17
drackyjr/cve-2025-3248-exploit

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…

★ 3 · 2025-11-21
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
kyaw-tun/blue-team-capstone

CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.

★ 0 · 2026-09-11
PoCs 1 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
LindHunt/CVE-2026-26211

Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

★ 1 · 2026-09-11
PoCs 2 ★ 1 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 2 repositories
JohenLastGen-JLG/CVE-2026-18351

CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 Unauthenticated Arbitrary File Upload -> RCE

★ 1 · 2026-09-11
ChiefYoru/Exploit-CVE-2026-18351

Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
abhinavagarwal07/scadapack-secure-lock-poc

Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-11 (1 month ago)

Fetching description from NVD…

Show 1 repositories
abdul-kalam2000/retbleed-speculative-execution-poc

Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mi…

★ 0 · 2026-09-11
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 1 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
hakaioffsec/CVE-2026-63642
★ 1 · 2026-09-10
PoCs 2 ★ 17 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 2 repositories
TarPeg007/CVE-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

★ 17 · 2026-09-02
BishopFox/CVE-2026-19490-check

Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490

★ 1 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
YonLiud/CVE-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later incorporates it into …

★ 0 · 2026-09-10
CVE-2022-24637
MULTI PoC
PoCs 7 ★ 5 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
Lay0us/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3

★ 5 · 2022-08-30
hupe1980/CVE-2022-24637

Open Web Analytics (OWA) - Unauthenticated Remote Code Execution

★ 5 · 2022-10-12
icebreack/CVE-2022-24637

FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)

★ 4 · 2022-11-15
Pflegusch/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution

★ 4 · 2023-04-08
0xM4hm0ud/CVE-2022-24637

Unauthenticated RCE in Open Web Analytics version <1.7.4

★ 3 · 2023-03-26
0xRyuk/CVE-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

★ 1 · 2023-08-22
PrinceAikinsBaidoo/CVE-2022-24637
★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
promasu/CVE-2026-73786

Might be used to share PoC and findings regarding CVE-2026-73786 in the future

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
squeeze440/inference-gateway-PoC

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

★ 0 · 2026-09-10
CVE-2026-66066
MULTI PoC
PoCs 7 ★ 30 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
Zer0SumGam3/CVE-2026-66066-POC

PoC for CVE-2026-66066 in Ruby on Rails

★ 23 · 2026-07-30
HackSpeak/CVE-2026-66066

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

★ 4 · 2026-08-04
0xsha/KindaRails2Shell

CVE-2026-66066 + File Read, RCE, Scanner, Lab

★ 3 · 2026-07-31
0xBlackash/CVE-2026-66066

CVE-2026-66066

★ 1 · 2026-07-31
shinthink/CVE-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged vari…

★ 1 · 2026-08-04
ivanesk315/CVE-2026-66066
★ 0 · 2026-09-10
PoCs 2 ★ 3 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 2 repositories
tar-xz/CVE-2026-53519-PoC

PoC exploit for CVE-2026-53519.

★ 3 · 2026-06-16
ivanesk315/CVE-2026-53519
★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
ivanesk315/CVE-2026-42613
★ 0 · 2026-09-10
PoCs 2 ★ 1 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 2 repositories
ivanesk315/CVE-2026-28496
★ 0 · 2026-09-10
CVE-2026-20253
MULTI PoC
PoCs 7 ★ 13 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 7 repositories
0xBlackash/CVE-2026-20253

CVE-2026-20253

★ 5 · 2026-06-13
HORKimhab/CVE-2026-20253

CVE-2026-20253 - Splunk Enterprise

★ 0 · 2026-06-14
fevar54/CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-

PoC de CVE-2026-20253: RCE pre-autenticacion en Splunk Enterprise.

★ 0 · 2026-06-26
pssec-io/CVE-2026-20253

POC for CVE-2026-20253

★ 0 · 2026-06-29
Het-Kalariya/CVE-2026-20253
★ 0 · 2026-07-18
ivanesk315/CVE-2026-20253
★ 0 · 2026-09-10
CVE-2023-25157
HOTMULTI PoC
PoCs 10 ★ 165 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 8 of 10 repositories
win3zz/CVE-2023-25157

CVE-2023-25157 - GeoServer SQL Injection - PoC

★ 165 · 2023-07-14
murataydemir/CVE-2023-25157-and-CVE-2023-25158

GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)

★ 13 · 2023-06-11
0x2458bughunt/CVE-2023-25157
★ 10 · 2023-06-10
7imbitz/CVE-2023-25157-checker

A script, written in golang. POC for CVE-2023-25157

★ 3 · 2024-02-02
charis3306/CVE-2023-25157

CVE-2023-25157 exp

★ 3 · 2025-04-24
dr-cable-tv/Geoserver-CVE-2023-25157

Geoserver SQL Injection Exploit

★ 2 · 2023-11-28
Rubikcuv5/CVE-2023-25157

GeoServer OGC Filter SQL Injection Vulnerabilities

★ 0 · 2023-07-31
custiya/geoserver-CVE-2023-25157
★ 0 · 2025-04-21
PoCs 3 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 3 repositories
Dungsocool/CVE-2020-13671-old

CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC

★ 0 · 2026-08-22
Dungsocool/CVE-2020-13671

CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC

★ 0 · 2026-08-22
ivanesk315/CVE-2020-13671
★ 0 · 2026-09-10
CVE-2026-60137
MULTI PoC
PoCs 11 ★ 10 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 8 of 11 repositories
codeb0ssx/Ultimate-wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…

★ 10 · 2026-07-18
Colere-Sys/wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

★ 3 · 2026-07-21
ebrasha/abdal-cve-2026-60137

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. …

★ 2 · 2026-07-24
h4cd0c/wp2shell

wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…

★ 0 · 2026-07-18
mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

★ 0 · 2026-07-21
northsia/CVE-2026-60137-With-Skip-SSL

Adding --insecure to skip ssl

★ 0 · 2026-07-26
michael-kanda/Wp2shell-ioc-scanner

Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and …

★ 0 · 2026-08-03
< Prev Page 36 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.