Fetching description from NVD…
Show 2 repositories
CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184
Fetching description from NVD…
thinkphp5.*Rce CVE-2018-20062
RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。
Fetching description from NVD…
CVE-2016-3223 - Draft or TODO
Fetching description from NVD…
Fetching description from NVD…
Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.
Fetching description from NVD…
Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)
CVE-2025-27636 PoC written in Python
Fetching description from NVD…
PoC for CVE-2026-77578 - Authenticated Arbitrary Local File Read in Xibo CMS
Fetching description from NVD…
CVE-2026-79387-PbootCMS-SQL-Injection
Fetching description from NVD…
PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet
Fetching description from NVD…
WonderCMS Authenticated RCE - CVE-2023-41425
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution in WonderC…
CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a crafted script …
CVE-2023-41425 (Wonder CMS XSS to RCE) exploit which serves required scripts locally. Good if you're lost at sea and have found a problem with your bike.
Wonder CMS RCE (XSS)
Xss injection, WonderCMS 3.2.0 -3.4.2
WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit
Fetching description from NVD…
Fetching description from NVD…
CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)
CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)
A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.
Exploiting SQL Injection Vulnerability in WP Fastest Cache (CVE-2023-6063)
CVE-2023-6063-PoC Exploit
Fetching description from NVD…
PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
[漏洞复现] 全球首款利用PHP默认环境(XAMPP)的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。
CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.
一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具
POC & $BASH script for CVE-2024-4577
PHP CGI Argument Injection vulnerability
PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template
PHP CGI Argument Injection (CVE-2024-4577) RCE
Fetching description from NVD…
CVE-2023-34468: Remote Code Execution via DB Components in Apache NiFi
PoC exploit for CVE-2023-34468 — RCE via H2 RUNSCRIPT in Apache NiFi <= 1.21.0
CVE-2023-34468 - Apache NiFi H2 RCE PoC
Educational proof-of-concept for CVE-2023-34468 affecting Apache NiFi. Demonstrates H2 JDBC URL abuse leading to authenticated RCE in vulnerable NiFi versions.
CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC
Writeup of the Hackthebox Helix machine
Fetching description from NVD…
CVE-2025-55752, Apache Tomcat that allows directory traversal via URL rewrite, and under certain conditions, leads to remote code execution (RCE) if HTTP PUT i…
基于 Docker 的重现环境,用于复现 Apache Tomcat 10.1.44 中的路径遍历漏洞 CVE-2025-55752。本实验场景可以复现官网报道的RCE
CVE-2025-55752:Tomcat 8.5 已 EOL,终版 8.5.100。Apache 逐条声明「8.5 也受影响」的 2025 CVE 有 14 条,其中 10 条在 NVD 按 8.5.100 查不到。离线单 jar,读 conf/ 判断你到底中了哪几条。
Fetching description from NVD…
CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/1…
Fetching description from NVD…
查出 Spring Boot 内嵌 Tomcat 的真实版本(pom 里没有),并对每条 2026 年 CVE 同时给出 ASF 官方评级与 GitHub 评级、触发条件、以及这条会不会进 Dependabot 告警 CVE-2026-41293
Fetching description from NVD…
Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your version lin…
Fetching description from NVD…
CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability
扫出你实际装的 Apache Shiro 模块与版本,逐条判定官方 26 条 CVE 里哪些真的落在你身上。按「CVE × 模块」判定,零依赖单 jar。 CVE-2026-49268
Fetching description from NVD…
Offline checker for Spring Cloud Config CVE-2026-40982 — tells you whether your version line has an OSS fix at all (3.1.x/4.1.x/4.2.x: it does not)
Fetching description from NVD…
pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs
CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.
CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets. Keep-alive, p…
cve-2026-29000 exploit
CVE-2026-29000 - pac4j-jwt Authentication Bypass PoC
Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).
Fetching description from NVD…
CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all …
Fetching description from NVD…
CVE-2025-55163 / CVE-2026-56819: offline checker for the 7 netty-codec-http2 CVEs. Tells you which ones you are exposed to, and the one version that fixes all …
Fetching description from NVD…
log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来) CVE-2026-4…
Fetching description from NVD…
Offline scanner telling you which of the 2026 Bouncy Castle CVEs actually apply to you - across BC, BC-LTS and BC-FJA (FIPS), which do not share a version sche…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.