Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
14New in 24h
366PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 2 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 2 repositories
HORKimhab/CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184

CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184

★ 0 · 2026-09-07
ivanesk315/CVE-2026-13181-Telerik
★ 0 · 2026-09-10
PoCs 4 ★ 6 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 4 repositories
NS-Sp4ce/thinkphp5.XRce

thinkphp5.*Rce CVE-2018-20062

★ 6 · 2019-03-17
yilin1203/CVE-2018-20062
★ 2 · 2022-11-07
shenhui35/RedArrow

RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。

★ 2 · 2025-09-16
Jasper2018/CVE-2018-20062
★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2016-3223

CVE-2016-3223 - Draft or TODO

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
Saku0512/CVE-2026-72815-poc
★ 0 · 2026-09-10
PoCs 1 ★ 1 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
arian-gogani/enforcement-coverage

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

★ 1 · 2026-09-10
CVE-2025-27636
MULTI PoC
PoCs 5 ★ 41 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 5 repositories
Crystallen1/CVE-2025-27636-demo
★ 0 · 2025-10-23
oscerd/CVE-2026-40453

Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)

★ 0 · 2026-07-08
AC8999/CVE-2025-27636-RCE-in-Apache-Camel

CVE-2025-27636 PoC written in Python

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-10 (1 month ago)

Fetching description from NVD…

Show 1 repositories
Soskalai/CVE-2026-77578

PoC for CVE-2026-77578 - Authenticated Arbitrary Local File Read in Xibo CMS

★ 0 · 2026-09-10
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
jhli07/CVE-2026-79387-PbootCMS-SQL-Injection

CVE-2026-79387-PbootCMS-SQL-Injection

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
l0lsec/openfire-ssrf-cve-2019-18394

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

★ 0 · 2026-09-09
CVE-2023-41425
MULTI PoC
PoCs 14 ★ 27 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 14 repositories
prodigiousMind/CVE-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

★ 27 · 2024-12-30
Tea-On/CVE-2023-41425-RCE-WonderCMS-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderC…

★ 8 · 2025-07-16
thefizzyfish/CVE-2023-41425-wonderCMS_RCE

CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script …

★ 3 · 2024-10-03
duck-sec/CVE-2023-41425

CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.

★ 3 · 2024-10-02
charlesgargasson/CVE-2023-41425

Wonder CMS RCE (XSS)

★ 1 · 2024-08-11
Raffli-Dev/CVE-2023-41425
★ 1 · 2024-09-03
Diegomjx/CVE-2023-41425-WonderCMS-Authenticated-RCE

Xss injection, WonderCMS 3.2.0 -3.4.2

★ 1 · 2026-09-09
xpltive/CVE-2023-41425

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

★ 1 · 2024-12-23
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
BrainBob/CVE-2026-76578
★ 0 · 2026-09-09
CVE-2023-6063
MULTI PoC
PoCs 5 ★ 29 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 5 repositories
motikan2010/CVE-2023-6063-PoC

CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)

★ 29 · 2023-11-15
Eulex0x/CVE-2023-6063

CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)

★ 9 · 2023-11-16
incommatose/CVE-2023-6063-PoC

A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.

★ 2 · 2025-07-16
hackersroot/CVE-2023-6063-PoC

Exploiting SQL Injection Vulnerability in WP Fastest Cache (CVE-2023-6063)

★ 0 · 2023-11-16
zhairiazzeddine/Exploit-CVE-2023-6063-PoC-Vuln

CVE-2023-6063-PoC Exploit

★ 0 · 2026-09-09
CVE-2024-4577
HOTMULTI PoC
PoCs 70 ★ 321 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 70 repositories
watchtowrlabs/CVE-2024-4577

PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC

★ 321 · 2024-06-22
xcanwin/CVE-2024-4577-PHP-RCE

[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。

★ 160 · 2024-07-21
TAM-K592/CVE-2024-4577

CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.

★ 75 · 2024-06-11
Night-have-dreams/php-cgi-Injector

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

★ 52 · 2025-03-29
11whoami99/CVE-2024-4577

POC & $BASH script for CVE-2024-4577

★ 43 · 2024-06-09
Chocapikk/CVE-2024-4577

PHP CGI Argument Injection vulnerability

★ 35 · 2026-01-24
ZephrFish/CVE-2024-4577-PHP-RCE

PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template

★ 33 · 2026-07-30
gh-ost00/CVE-2024-4577-RCE

PHP CGI Argument Injection (CVE-2024-4577) RCE

★ 25 · 2024-08-20
CVE-2023-34468
MULTI PoC
PoCs 7 ★ 8 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 7 repositories
mbadanoiu/CVE-2023-34468

CVE-2023-34468: Remote Code Execution via DB Components in Apache NiFi

★ 8 · 2023-12-01
sbouabid-sec/CVE-2023-34468-POC

PoC exploit for CVE-2023-34468 — RCE via H2 RUNSCRIPT in Apache NiFi <= 1.21.0

★ 4 · 2026-05-10
Jeanpt/CVE-2023-34468

CVE-2023-34468 - Apache NiFi H2 RCE PoC

★ 1 · 2026-05-10
spikeyjr/CVE-2023-34468-PoC

Educational proof-of-concept for CVE-2023-34468 affecting Apache NiFi. Demonstrates H2 JDBC URL abuse leading to authenticated RCE in vulnerable NiFi versions.

★ 0 · 2026-06-16
ozcanpng/CVE-2023-34468

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC

★ 0 · 2026-07-12
luiskrnr/HTB_Helix_CVE-2023-34468

Writeup of the Hackthebox Helix machine

★ 0 · 2026-09-09
CVE-2025-55752
MULTI PoC
PoCs 5 ★ 13 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 5 repositories
masahiro331/CVE-2025-55752
★ 13 · 2025-10-31
TAM-K592/CVE-2025-55752

CVE-2025-55752, Apache Tomcat that allows directory traversal via URL rewrite, and under certain conditions, leads to remote code execution (RCE) if HTTP PUT i…

★ 13 · 2025-10-28
AuroraSec-Pivot/CVE-2025-55752

基于 Docker 的重现环境,用于复现 Apache Tomcat 10.1.44 中的路径遍历漏洞 CVE-2025-55752。本实验场景可以复现官网报道的RCE

★ 2 · 2025-11-05
Jimmy01240397/CVE-2025-55752
★ 0 · 2026-02-19
xiaoqiMikko/tomcat85-check

CVE-2025-55752:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5 也受影响」的 2025 CVE 有 14 条,其中 10 条在 NVD 按 8.5.100 查不到。离线单 jar,读 conf/ 判断你到底中了哪几条。

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/tomcat-line-check

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/1…

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/tomcat-check

查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/thymeleaf-check

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your version lin…

★ 0 · 2026-09-09
PoCs 2 ★ 2 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 2 repositories
sassoftware/shiro

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

★ 2 · 2026-09-09
xiaoqiMikko/shiro-check

扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/scc-check

Offline checker for Spring Cloud Config CVE-2026-40982 — tells you whether your version line has an OSS fix at all (3.1.x/4.1.x/4.2.x: it does not)

★ 0 · 2026-09-09
CVE-2026-29000
MULTI PoC
PoCs 21 ★ 9 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
kernelzeroday/CVE-2026-29000

pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs

★ 9 · 2026-03-06
Strikoder-Premium/CVE-2026-29000-pac4j-jwt

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

★ 3 · 2026-05-03
tc4dy/CVE-2026-29000-PoC-Exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, p…

★ 3 · 2026-06-06
RootX111/cve-2026-29000

cve-2026-29000 exploit

★ 2 · 2026-03-16
manbahadurthapa1248/CVE-2026-29000---pac4j-jwt-Authentication-Bypass-PoC

CVE-2026-29000 - pac4j-jwt Authentication Bypass PoC

★ 1 · 2026-03-13
otuva/CVE-2026-29000
★ 1 · 2026-03-13
PtechAmanja/CVE-2026-29000-pac4j-jwt-auth-bypass

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

★ 1 · 2026-03-24
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/netty-http2-check

CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all …

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/netty-http2-check

CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all …

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/log4j-check

log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来) CVE-2026-4…

★ 0 · 2026-09-09
PoCs 1 ★ 0 Last push 2026-09-09 (1 month ago)

Fetching description from NVD…

Show 1 repositories
xiaoqiMikko/bc-check

Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version sche…

★ 0 · 2026-09-09
< Prev Page 37 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.