Fetching description from NVD…
Show 1 repositories
Sanitized XenForo write-up and proof of concept for CVE-2026-73311.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
Sanitized XenForo write-up and proof of concept for CVE-2026-73311.
Fetching description from NVD…
Sanitized XenForo write-up and proof of concept for CVE-2026-73310.
Fetching description from NVD…
Sanitized XenForo write-up and proof of concept for CVE-2026-73309.
Fetching description from NVD…
Fetching description from NVD…
Security-hardened fork of sift 17.1.3 for CVE-2026-85625. Not affiliated with crcn/sift.js.
Fetching description from NVD…
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
Public PoC for CVE-2026-82222
GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE
⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), mul…
Fetching description from NVD…
CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82
CVE-2026-85046
Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml…
Fetching description from NVD…
Fetching description from NVD…
This repository contains an exploit for CVE-2024-34361, a critical Pi-hole vulnerability (CVSS 8.6). It uses SSRF to achieve RCE by exploiting improper URL val…
Fetching description from NVD…
This exploit was written to study some concepts, enjoy!
Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the flag. Include…
From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented
Fetching description from NVD…
SPIP (CVE-2024-23659) script with native python3 dependencies
Fetching description from NVD…
Fetching description from NVD…
Fetching description from NVD…
Technical write-up and PoC for CVE-2026-8069 in Acer NitroSense and PredatorSense
Fetching description from NVD…
PoC for the CVE-2026-69451 - Fastprox EoP
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.
CVE-2026-8732 | WP Maps Pro <= 6.1.0 | Unauthenticated Privilege Escalation
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation
CVE-2026-8732 - Draft (WordPress)
Fetching description from NVD…
CVE-2026-10795 – UpdraftPlus Authentication Bypass
CVE-2026-10795 - Draft or TODO
Fetching description from NVD…
Public reference for CVE-2026-52307
Fetching description from NVD…
Assessment script — CVE-2025-47981 SPNEGO NEGOEX heap overflow (CVSS 9.8, wormable). Checks ntoskrnl.exe version, PKU2U registry key, exposed ports. Detection …
Fetching description from NVD…
PoC for CVE-2023-4911
CVE-2023-4911 proof of concept
Exploit tool for CVE-2023-4911, targeting the 'Looney Tunables' glibc vulnerability in various Linux distributions.
CVE-2023-4911
Looney Tunables Local privilege escalation (CVE-2023-4911) workshop
https://www.qualys.com/2023/10/03/cve-2023-4911/looney-tunables-local-privilege-escalation-glibc-ld-so.txt
Proof of concept for CVE-2023-4911 (Looney Tunables) discovered by Qualys Threat Research Unit
Fetching description from NVD…
ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container
Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution
Tool for exploit CVE-2015-3306
ProFTPd 1.3.5 - File Copy
Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development
An implementation of CVE-2015-3306
This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.
Fetching description from NVD…
This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.