Fetching description from NVD…
Show 1 repositories
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocati…
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706 conditional-revocati…
Fetching description from NVD…
CVE-2026-51990 - Draft or TODO
Fetching description from NVD…
Exploit for the CVE-2023-23397
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.
Simple PoC in PowerShell for CVE-2023-23397
Proof of Concept for CVE-2023-23397 in Python
Python script for sending e-mails with CVE-2023-23397 payload using SMTP
Fetching description from NVD…
CVE-2025-3248 Langflow RCE Exploit
A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。
Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]
POC of CVE-2025-3248, RCE of LangFlow
Mass-CVE-2025-3248
Langflow Remote Code Execution
A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in La…
Fetching description from NVD…
CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.
Fetching description from NVD…
Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.
Fetching description from NVD…
CVE-2026-18351 — Drag and Drop File Upload for Elementor Forms <= 1.6.0 Unauthenticated Arbitrary File Upload -> RCE
Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥
Fetching description from NVD…
Sanitized offline fixture verifier for CVE-2026-81861 in SCADAPack Secure Lock
Fetching description from NVD…
Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mi…
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC
Safely detect Citrix NetScaler SAML auth bypass CVE-2026-19490
Fetching description from NVD…
Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.
Fetching description from NVD…
The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later incorporates it into …
Fetching description from NVD…
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
Open Web Analytics (OWA) - Unauthenticated Remote Code Execution
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
Open Web Analytics 1.7.3 - Remote Code Execution
Unauthenticated RCE in Open Web Analytics version <1.7.4
Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2
Fetching description from NVD…
Might be used to share PoC and findings regarding CVE-2026-73786 in the future
Fetching description from NVD…
PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).
Fetching description from NVD…
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing
CVE-2026-66066 + File Read, RCE, Scanner, Lab
CVE-2026-66066
CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged vari…
Fetching description from NVD…
PoC exploit for CVE-2026-53519.
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
CVE-2026-20253
CVE-2026-20253 - Splunk Enterprise
PoC de CVE-2026-20253: RCE pre-autenticacion en Splunk Enterprise.
POC for CVE-2026-20253
Fetching description from NVD…
CVE-2023-25157 - GeoServer SQL Injection - PoC
GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)
A script, written in golang. POC for CVE-2023-25157
CVE-2023-25157 exp
Geoserver SQL Injection Exploit
GeoServer OGC Filter SQL Injection Vulnerabilities
Fetching description from NVD…
CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC
CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC
Fetching description from NVD…
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…
Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030
Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection vulnerability. …
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for…
CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)
Adding --insecure to skip ssl
Read-only-by-default WordPress incident-response scanner for the “wp2shell” attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin, database and …
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.