Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
362PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 1 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 1 repositories
ddrvahandzo90-hue/CVE-2026-42031-SQL-Injection-Scanner

CVE-2026-42031 SQL Injection Scanner for CKAN DataStore

★ 1 · 2026-09-07
PoCs 3 ★ 428 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 3 repositories
jailbreakdotparty/dirtyZero

Simple customization toolbox, utilizing CVE-2025-24203. Supports iOS 16.0 - iOS 18.3.2.

★ 428 · 2026-09-07
GeoSn0w/CVE-2025-24203-iOS-Exploit-With-Error-Logging

Slightly improved exploit of the CVE-2025-24203 iOS vulnerability by Ian Beer of Google Project Zero

★ 41 · 2025-10-21
pxx917144686/iDevice_ZH

CVE-2025-24203漏洞

★ 24 · 2025-05-25
PoCs 1 ★ 0 Last push 2026-09-07 (1 month ago)

Fetching description from NVD…

Show 1 repositories
Eliot-code/CVE-2026-52924
★ 0 · 2026-09-07
CVE-2025-31324
MULTI PoC
PoCs 21 ★ 25 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 of 21 repositories
redrays-io/CVE-2025-31324

CVE-2025-31324, SAP Exploit

★ 25 · 2025-04-28
antichainalysis/sap-netweaver-0day-CVE-2025-31324

sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324

★ 22 · 2025-08-15
Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

★ 9 · 2025-06-06
NULLTRACE0X/CVE-2025-31324
★ 9 · 2025-05-12
ODST-Forge/CVE-2025-31324_PoC

Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader

★ 7 · 2025-04-28
rf-peixoto/sap_netweaver_cve-2025-31324-

Research Purposes only

★ 5 · 2025-05-07
rxerium/CVE-2025-31324

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious ex…

★ 4 · 2025-10-14
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-677752506e

Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of gitroomhq/pos…

★ 0 · 2026-09-06
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
joaovicdev/EXPLOIT-CVE-2026-42559

Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport

★ 0 · 2026-09-06
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
joaovicdev/EXPLOIT-CVE-2024-7804

Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)

★ 0 · 2026-09-06
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-456dd8a245

Security-research lab reproducing CVE-2026-41414 (pull_request_target pwn in .github/workflows/pr.yml) — snapshot of skim-rs/skim @ ca986f4, not a fork.

★ 0 · 2026-09-06
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-5bce203f66

Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml, snapshot of core…

★ 0 · 2026-09-06
PoCs 4 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 4 repositories
codeb0ssx/CVE-2026-64849-PoC
★ 0 · 2026-08-18
BiuTrap/CVE-2026-64849

CVE-2026-64849 PoC

★ 0 · 2026-08-19
zavisco/CVE-2026-64849.yaml
★ 0 · 2026-08-19
isaca0315/CVE-2026-64849-poc-lab

este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah

★ 0 · 2026-09-06
PoCs 2 ★ 1 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 2 repositories
pvharmo2/gha-lab-360f77d0d4

Authorized security-research lab: reproduction of CVE-2026-39866 (GHSA-9prc-pp2c-3427) — workflow_dispatch input template injection in .github/workflows/releas…

★ 1 · 2026-09-06
abhayclasher/CVE-2026-39866
★ 0 · 2026-04-11
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-61c59f4acb

Security-research lab: controlled reproduction of CVE-2026-33075 (pwn request in labring/FastGPT preview-image workflow, pull_request_target + checkout-of-fork…

★ 0 · 2026-09-06
CVE-2026-44578
MULTI PoC
PoCs 8 ★ 77 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 repositories
ynsmroztas/nextssrf

NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF

★ 77 · 2026-05-15
dinosn/CVE-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

★ 9 · 2026-05-16
love07oj/nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and real-world sca…

★ 8 · 2026-05-15
0xBlackash/CVE-2026-44578

CVE-2026-44578

★ 1 · 2026-05-17
lxxexxbxx/CVE-2026-44578

CVE-2026-44578 PoC

★ 1 · 2026-08-20
panchocosil/verify-ghsa-c4j6-fc7j-m34r

OOB verifier for GHSA-c4j6-fc7j-m34r / CVE-2026-44578 (Next.js WebSocket-upgrade SSRF)

★ 0 · 2026-05-13
tocong282/CVE-2026-44578-PoC
★ 0 · 2026-05-15
isaca0315/CVE-2026-44578-next-js-ssrf

este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah

★ 0 · 2026-09-06
PoCs 2 ★ 1 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 2 repositories
Virgula0/CVE-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

★ 1 · 2026-08-12
0xCyp1337/CVE-2026-44402
★ 0 · 2026-09-06
PoCs 4 ★ 1 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 4 repositories
HORKimhab/CVE-Wordpress

CVE-2026-49777, CVE-2026-10735

★ 1 · 2026-08-08
izxci/CVE-2026-49777

CVE-2026-49777 - ShapedPlugin Product Slider Pro for WooCommerce Backdoor RCE

★ 0 · 2026-06-12
katranSefa/CVE-2026-49777
★ 0 · 2026-09-06
CVE-2026-6279
MULTI PoC
PoCs 5 ★ 3 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 5 repositories
zycoder0day/CVE-2026-6279

CVE-2026-6279 — Avada Builder <= 3.15.2 Unauthenticated RCE via call_user_func()

★ 3 · 2026-05-23
87achrafg-stack/CVE-2026-6279.py

CVE-2026-6279

★ 1 · 2026-06-13
xxconi/CVE-2026-6279

CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via …

★ 0 · 2026-06-11
87achrafg-stack/CVE-2026-6279
★ 0 · 2026-06-13
katranSefa/CVE-2026-6279
★ 0 · 2026-09-06
PoCs 4 ★ 3 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 4 repositories
0xCyp1337/CVE-2026-19598-
★ 3 · 2026-09-06
DeadExpl0it/CVE-2026-19598-PoC

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

★ 1 · 2026-08-21
sag-asab/CVE-2026-19598

Custom Content Types and Fields plugin for WordPress

★ 1 · 2026-08-21
ksotaria1337/CVE-2026-19598
★ 0 · 2026-08-18
CVE-2023-7028
HOTMULTI PoC
PoCs 18 ★ 245 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 8 of 18 repositories
Vozec/CVE-2023-7028

This repository presents a proof-of-concept of CVE-2023-7028

★ 245 · 2024-01-13
RandomRobbieBF/CVE-2023-7028

CVE-2023-7028

★ 58 · 2024-01-12
Esonhugh/gitlab_honeypot

CVE-2023-7028 killer

★ 4 · 2024-01-18
duy-31/CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5…

★ 3 · 2024-01-12
Trackflaw/CVE-2023-7028-Docker

Repository to install CVE-2023-7028 vulnerable Gitlab instance

★ 3 · 2024-01-25
sariamubeen/CVE-2023-7028
★ 3 · 2025-02-17
thanhlam-attt/CVE-2023-7028
★ 2 · 2024-01-23
hackeremmen/gitlab-exploit

GitLab CVE-2023-7028

★ 1 · 2024-01-28
PoCs 2 ★ 3 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 2 repositories
0xBlackash/CVE-2026-27876

CVE-2026-27876

★ 3 · 2026-03-30
atiilla/CVE-2026-27876

Grafana SQL Expressions Arbitrary File Write to RCE

★ 0 · 2026-09-06
CVE-2025-24799
MULTI PoC
PoCs 5 ★ 36 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 5 repositories
MatheuZSecurity/Exploit-CVE-2025-24799

CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection

★ 36 · 2025-04-15
MuhammadWaseem29/CVE-2025-24799

CVE-2025-24799 SQLi Scanner

★ 5 · 2025-04-03
Rosemary1337/CVE-2025-24799

CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection

★ 0 · 2025-09-08
airbus-cert/CVE-2025-24799-scanner

Scanner for GLPI CVE-2025-24799 vulnerability

★ 0 · 2025-09-16
galisko/CVE-2025-24799
★ 0 · 2026-09-06
PoCs 1 ★ 0 Last push 2026-09-06 (1 month ago)

Fetching description from NVD…

Show 1 repositories
athosgonzaga/CVE-2021-3030

Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx

★ 0 · 2026-09-06
PoCs 2 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 2 repositories
HORKimhab/CVE-2026-28956

CVE-2026-28956 - Draft or TODO

★ 0 · 2026-08-12
eddinos2/CVE-2026-28956-jxl-messages-surface

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

★ 0 · 2026-09-05
PoCs 2 ★ 9 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 2 repositories
ColdFusionX/Keycloak-12.0.1-CVE-2020-10770

Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)

★ 9 · 2022-07-11
0xlyvio/CVE-2020-10770-keycloak-exploit-poc

Keycloak Blind SSRF POC

★ 2 · 2026-09-05
PoCs 4 ★ 6 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 4 repositories
0x240x23elu/CVE-2026-1529

Keycloak: Unauthorized organization registration via improper invitation token validation

★ 6 · 2026-02-11
0xlyvio/CVE-2026-1529-Keycloak-Exploit-Tool

Keycloak: Unauthorized organization registration via improper invitation token validation

★ 3 · 2026-09-05
ninjazan420/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token validation. Th…

★ 1 · 2026-02-10
ackemed/CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token validation. Th…

★ 0 · 2026-02-10
PoCs 2 ★ 1 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 2 repositories
eddinos2/CVE-2026-64747

AppleAVE2 kernel driver wire-format research and macOS reachability PoC for CVE-2026-64747.

★ 1 · 2026-09-05
yiyeshi0-hash/ave263-chain

iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)

★ 0 · 2026-08-17
< Prev Page 41 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.