Fetching description from NVD…
Show 1 repositories
CVE-2026-42031 SQL Injection Scanner for CKAN DataStore
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
CVE-2026-42031 SQL Injection Scanner for CKAN DataStore
Fetching description from NVD…
Simple customization toolbox, utilizing CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.
Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero
CVE-2025-24203漏洞
Fetching description from NVD…
Fetching description from NVD…
CVE-2025-31324, SAP Exploit
sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
Research Purposes only
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious ex…
Fetching description from NVD…
Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of gitroomhq/pos…
Fetching description from NVD…
Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport
Fetching description from NVD…
Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)
Fetching description from NVD…
Security-research lab reproducing CVE-2026-41414 (pull_request_target pwn in .github/workflows/pr.yml) — snapshot of skim-rs/skim @ ca986f4, not a fork.
Fetching description from NVD…
Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml, snapshot of core…
Fetching description from NVD…
CVE-2026-64849 PoC
este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah
Fetching description from NVD…
Authorized security-research lab: reproduction of CVE-2026-39866 (GHSA-9prc-pp2c-3427) — workflow_dispatch input template injection in .github/workflows/releas…
Fetching description from NVD…
Security-research lab: controlled reproduction of CVE-2026-33075 (pwn request in labring/FastGPT preview-image workflow, pull_request_target + checkout-of-fork…
Fetching description from NVD…
NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF
CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.
Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world sca…
CVE-2026-44578
CVE-2026-44578 PoC
OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)
este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah
Fetching description from NVD…
Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1
Fetching description from NVD…
CVE-2026-49777, CVE-2026-10735
CVE-2026-49777 - ShapedPlugin Product Slider Pro for WooCommerce Backdoor RCE
Fetching description from NVD…
CVE-2026-6279 — Avada Builder <= 3.15.2 Unauthenticated RCE via call_user_func()
CVE-2026-6279
CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via …
Fetching description from NVD…
Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.
Custom Content Types and Fields plugin for WordPress
Fetching description from NVD…
This repository presents a proof-of-concept of CVE-2023-7028
CVE-2023-7028
CVE-2023-7028 killer
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5…
Repository to install CVE-2023-7028 vulnerable Gitlab instance
GitLab CVE-2023-7028
Fetching description from NVD…
CVE-2026-27876
Grafana SQL Expressions Arbitrary File Write to RCE
Fetching description from NVD…
CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection
CVE-2025-24799 SQLi Scanner
CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection
Scanner for GLPI CVE-2025-24799 vulnerability
Fetching description from NVD…
Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx
Fetching description from NVD…
CVE-2026-28956 - Draft or TODO
iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.
Fetching description from NVD…
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
Keycloak Blind SSRF POC
Fetching description from NVD…
Keycloak: Unauthorized organization registration via improper invitation token validation
Keycloak: Unauthorized organization registration via improper invitation token validation
CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token validation. Th…
CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token validation. Th…
Fetching description from NVD…
AppleAVE2 kernel driver wire-format research and macOS reachability PoC for CVE-2026-64747.
iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.