Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
14New in 24h
366PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-73311

Sanitized XenForo write-up and proof of concept for CVE-2026-73311.

★ 0 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-73310

Sanitized XenForo write-up and proof of concept for CVE-2026-73310.

★ 0 · 2026-09-08
PoCs 1 ★ 1 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
BomboBombone/CVE-2026-73309

Sanitized XenForo write-up and proof of concept for CVE-2026-73309.

★ 1 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
lgranadoi/sift-hardened

Security-hardened fork of sift 17.1.3 for CVE-2026-85625. Not affiliated with crcn/sift.js.

★ 0 · 2026-09-08
CVE-2026-82222
MULTI PoC
PoCs 5 ★ 16 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 5 repositories
dinosn/givewp-cve-2026-82222-rce-lab

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

★ 16 · 2026-08-30
UdinChan/cve-2026-82222-poc

Public PoC for CVE-2026-82222

★ 1 · 2026-08-30
R0x19/CVE-2026-82222

GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE

★ 0 · 2026-08-31
GhostlyrootB2H/CVE-2026-82222

⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), mul…

★ 0 · 2026-09-08
CVE-2026-85046
MULTI PoC
PoCs 6 ★ 9 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 6 repositories
atiilla/CVE-2026-85046

CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82

★ 9 · 2026-09-08
adriyansyah-mf/cve-2026-85046-poc
★ 6 · 2026-09-05
HORKimhab/CVE-2026-85046

CVE-2026-85046

★ 1 · 2026-09-04
ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine

Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine

★ 0 · 2026-09-04
Eliot-code/CVE-2026-85046
★ 0 · 2026-09-07
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-b1fe4918c0

Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml…

★ 0 · 2026-09-08
PoCs 1 ★ 1 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 1 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
T0X1Cx/CVE-2024-34361-Pi-Hole-SSRF-to-RCE

This repository contains an exploit for CVE-2024-34361, a critical Pi-hole vulnerability (CVSS 8.6). It uses SSRF to achieve RCE by exploiting improper URL val…

★ 1 · 2026-09-08
PoCs 3 ★ 2 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 3 repositories
M41doror/cve-2010-4221

This exploit was written to study some concepts, enjoy!

★ 2 · 2017-10-22
Mafiosohack/Offensive-lab-2

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the flag. Include…

★ 0 · 2025-12-07
diegslva/cve-2010-4221-lab

From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented

★ 0 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
amis13/SPIP-CVE-2024-23659-

SPIP (CVE-2024-23659) script with native python3 dependencies

★ 0 · 2026-09-08
PoCs 1 ★ 2 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
0xCyp1337/CVE-2026-57811
★ 2 · 2026-09-08
PoCs 1 ★ 1 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
Saku0512/CVE-2026-72744-poc
★ 1 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
S1eezer/CVE-2026-8069

Technical write-up and PoC for CVE-2026-8069 in Acer NitroSense and PredatorSense

★ 0 · 2026-09-08
PoCs 1 ★ 2 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
fj016/CVE-2026-69451-PoC

PoC for the CVE-2026-69451 - Fastprox EoP

★ 2 · 2026-09-08
CVE-2026-8732
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-306 Published 2026-05-29 PoCs 6 ★ 8 Last push 2026-09-08 (1 month ago)

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.

Show 6 repositories
p3Nt3st3r-sTAr/CVE-2026-8732-POC
★ 8 · 2026-06-01
zycoder0day/CVE-2026-8732

CVE-2026-8732 | WP Maps Pro <= 6.1.0 | Unauthenticated Privilege Escalation

★ 3 · 2026-05-30
Jenderal92/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

★ 3 · 2026-05-31
fientix/CVE-2026-8732-PoC

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

★ 2 · 2026-09-08
xShadow-Here/CVE-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation

★ 1 · 2026-05-30
HORKimhab/CVE-2026-8732

CVE-2026-8732 - Draft (WordPress)

★ 0 · 2026-06-01
PoCs 3 ★ 2 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 3 repositories
izxci/CVE-2026-10795

CVE-2026-10795 – UpdraftPlus Authentication Bypass

★ 2 · 2026-06-12
HORKimhab/CVE-2026-10795

CVE-2026-10795 - Draft or TODO

★ 0 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
linan-OO/CVE-2026-52307

Public reference for CVE-2026-52307

★ 0 · 2026-09-08
PoCs 1 ★ 0 Last push 2026-09-08 (1 month ago)

Fetching description from NVD…

Show 1 repositories
HKenzoKimura/CVE-2025-47981

Assessment script — CVE-2025-47981 SPNEGO NEGOEX heap overflow (CVSS 9.8, wormable). Checks ntoskrnl.exe version, PKU2U registry key, exposed ports. Detection …

★ 0 · 2026-09-08
CVE-2023-4911
HOTMULTI PoC
PoCs 21 ★ 393 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
leesh3288/CVE-2023-4911

PoC for CVE-2023-4911

★ 393 · 2023-10-04
RickdeJager/CVE-2023-4911

CVE-2023-4911 proof of concept

★ 167 · 2023-10-08
chaudharyarjun/LooneyPwner

Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.

★ 43 · 2023-10-18
ruycr4ft/CVE-2023-4911

CVE-2023-4911

★ 19 · 2023-10-11
KernelKrise/CVE-2023-4911

Looney Tunables Local privilege escalation (CVE-2023-4911) workshop

★ 18 · 2024-10-01
Green-Avocado/CVE-2023-4911

https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt

★ 15 · 2023-10-05
Diego-AltF4/CVE-2023-4911

Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit

★ 8 · 2024-11-03
CVE-2015-3306
HOTMULTI PoC
PoCs 18 ★ 152 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 8 of 18 repositories
t0kx/exploit-CVE-2015-3306

ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

★ 152 · 2018-04-07
nootropics/propane

Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution

★ 2 · 2015-06-01
xyk0x/cpx_proftpd

Tool for exploit CVE-2015-3306

★ 1 · 2015-04-22
davidtavarez/CVE-2015-3306

ProFTPd 1.3.5 - File Copy

★ 1 · 2017-07-29
cd6629/CVE-2015-3306-Python-PoC

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

★ 1 · 2020-12-24
0xm4ud/ProFTPD_CVE-2015-3306
★ 1 · 2021-06-07
jptr218/proftpd_bypass

An implementation of CVE-2015-3306

★ 1 · 2021-08-21
cybersensei-EH/hackviser_labs_CVE-2015-3306

This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.

★ 1 · 2025-11-02
PoCs 1 ★ 0 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 1 repositories
luel-4013/misfortune-cookie

This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE…

★ 0 · 2026-09-07
< Prev Page 39 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.