Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
361PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
eddinos2/CVE-2026-64705

Root-cause analysis and crash-tier PoC for CVE-2026-64705, an HFS xattr kernel heap overflow on macOS.

★ 0 · 2026-09-05
PoCs 1 ★ 1 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
eddinos2/CVE-2026-78938

V8 TurboFan CheckMaps type-confusion research and compressed-heap R/W exploit notes for CVE-2026-78938.

★ 1 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
mngunibanda1-prog/Jozini-network-scanner

# Jozini Network Scanner Built in Termux at KwaQondile Library, Jozini KZN Tools: - scanner.py: Port scanner with banner grabbing (20 ports + report saving) -…

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
Tenor-Z/CVE-2025-4255---Buffer-Overflow

Exploit Framework for CVE-2025-4255

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
0xTerror/CVE-2026-52774-YESWIKI-XSS

a reflected XSS vulnerability in YesWiki's Bazar widget handler.

★ 0 · 2026-09-05
PoCs 1 ★ 1 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
hackpatato/CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules

★ 1 · 2026-09-05
CVE-2025-1094
MULTI PoC
PoCs 6 ★ 41 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 6 repositories
soltanali0/CVE-2025-1094-Exploit

WebSocket and SQL Injection Exploit Script

★ 41 · 2025-02-27
aninfosec/CVE-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject ma…

★ 1 · 2025-06-26
skraft9/CVE-2024-12356

Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)

★ 1 · 2026-09-05
PinkArmor/CVE-2025-1094-Lab-Setup
★ 0 · 2025-10-19
TranDongA3/POC-CVE-2025-1094
★ 0 · 2026-05-16
PoCs 1 ★ 1 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
skraft9/CVE-2024-12356

Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)

★ 1 · 2026-09-05
PoCs 1 ★ 2 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
mhtsec/CVE-2026-84645

Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2

★ 2 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
katranSefa/CVE-2026-3326
★ 0 · 2026-09-05
CVE-2026-56290
MULTI PoC
PoCs 5 ★ 5 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 5 repositories
Jenderal92/CVE-2026-56290

CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploade…

★ 5 · 2026-07-08
shinthink/pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

★ 3 · 2026-07-04
sagsooz/PageBuilderCK-CVE-2026-56290-Exploit

Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter

★ 2 · 2026-07-04
ChiefYoru/CVE-2026-56290_PoC

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

★ 0 · 2026-07-19
katranSefa/CVE-2026-56290
★ 0 · 2026-09-05
PoCs 2 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 2 repositories
Nxploited/CVE-2026-15981

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

★ 0 · 2026-07-26
katranSefa/CVE-2026-15981
★ 0 · 2026-09-05
CVE-2026-3891
MULTI PoC
PoCs 9 ★ 21 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 8 of 9 repositories
m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

★ 21 · 2026-07-20
joshuavanderpoll/CVE-2026-3891

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC

★ 7 · 2026-03-13
Nxploited/CVE-2026-3891

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

★ 6 · 2026-03-27
shinthink/CVE-2026-3891

Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8

★ 4 · 2026-07-21
AnggaTechI/Mass-Scanner-CVE-2026-3891

CVE-2026-3891 Mass Scanning

★ 2 · 2026-04-16
willygailo/CVE-2026-3891-Linux

⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions …

★ 2 · 2026-05-31
Ch4120N/CVE-2026-3891

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

★ 2 · 2026-08-03
VeronnX666/CVE-2026-3891

This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.

★ 0 · 2026-07-19
PoCs 3 ★ 2 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 3 repositories
Nxploited/CVE-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

★ 2 · 2026-08-16
ghostpels/CVE-2026-18366

CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).

★ 0 · 2026-08-20
katranSefa/CVE-2026-18366
★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
ghostpels/CVE-2026-75865

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

★ 0 · 2026-09-05
CVE-2026-32475
MULTI PoC
PoCs 6 ★ 12 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 6 repositories
absholi7ly/Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload …

★ 12 · 2026-08-21
dinosn/cve-2026-32475-elementor-pro-lab

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

★ 8 · 2026-09-05
Boreas37/CVE-2026-32475-PoC

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

★ 6 · 2026-08-25
sahmsec/CVE-2026-32475
★ 1 · 2026-08-27
4minx/CVE-2026-32475

CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE

★ 1 · 2026-09-05
0xBlackash/CVE-2026-32475

CVE-2026-32475

★ 0 · 2026-08-22
CVE-2023-42793
MULTI PoC
PoCs 17 ★ 44 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 8 of 17 repositories
H454NSec/CVE-2023-42793

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

★ 44 · 2024-05-22
B4l3rI0n/CVE-2023-42793

JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793

★ 11 · 2024-04-24
Zenmovie/CVE-2023-42793

PoC of CVE-2023-42793

★ 9 · 2023-10-11
hotplugin0x01/CVE-2023-42793

JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 POC

★ 2 · 2024-05-06
junnythemarksman/CVE-2023-42793

TeamCity CVE-2023-42793 exploit written in Rust

★ 1 · 2024-05-27
hhesenjan/CVE-2023-42793

TeamCity RCE for Linux (CVE-2023-42793)

★ 1 · 2024-07-05
SwiftSecur/teamcity-exploit-cve-2023-42793

teamcity-exploit-cve-2023-42793

★ 1 · 2024-11-06
syaifulandy/Nuclei-Template-CVE-2023-42793.yaml

Windows & linux support

★ 1 · 2025-05-11
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
goldendivider/gpgsm-cve-2026-57062-cms-gcm-short-tag

gpgsm CVE-2026-57062 exploit POC

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-27771

CVE-2026-27771

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
joaovicdev/EXPLOIT-CVE-2026-22778
★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
sirredbeard/WebKitGTK-DND-Fix

Private research and validation for WebKitGTK file DnD restore (CVE-2025-13947 follow-up)

★ 0 · 2026-09-05
PoCs 1 ★ 3 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
rmhowe425/POC-CVE-2026-7873

PoC exploit code for CVE-2026-7873

★ 3 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-4a8fad8536

Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt…

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-ed7a1740c4

Security-research lab: controlled reproduction of GHSA-3g6g-gq4r-xjm9 / CVE-2026-35580 (GitHub Actions workflow_dispatch input shell injection) against a pinne…

★ 0 · 2026-09-05
PoCs 1 ★ 0 Last push 2026-09-05 (1 month ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-85f022290a

Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml — snapshot of njz…

★ 0 · 2026-09-05
< Prev Page 42 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.