Fetching description from NVD…
Show 1 repositories
Root-cause analysis and crash-tier PoC for CVE-2026-64705, an HFS xattr kernel heap overflow on macOS.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
Root-cause analysis and crash-tier PoC for CVE-2026-64705, an HFS xattr kernel heap overflow on macOS.
Fetching description from NVD…
V8 TurboFan CheckMaps type-confusion research and compressed-heap R/W exploit notes for CVE-2026-78938.
Fetching description from NVD…
# Jozini Network Scanner Built in Termux at KwaQondile Library, Jozini KZN Tools: - scanner.py: Port scanner with banner grabbing (20 ports + report saving) -…
Fetching description from NVD…
Exploit Framework for CVE-2025-4255
Fetching description from NVD…
a reflected XSS vulnerability in YesWiki's Bazar widget handler.
Fetching description from NVD…
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
Fetching description from NVD…
WebSocket and SQL Injection Exploit Script
It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject ma…
Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)
Fetching description from NVD…
Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)
Fetching description from NVD…
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2
Fetching description from NVD…
Fetching description from NVD…
CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploade…
📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE
Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter
The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Fetching description from NVD…
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
Fetching description from NVD…
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8
CVE-2026-3891 Mass Scanning
⚡ This tool exploits CVE-2026-3891, a critical unauthenticated arbitrary file upload vulnerability found in the Pix for WooCommerce WordPress plugin (versions …
PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.
This tool was created solely for educational purposes, not for criminal activities or anything of the sort. Do not misuse this tool. Good luck trying it out.
Fetching description from NVD…
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).
Fetching description from NVD…
Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC
Fetching description from NVD…
CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of empty upload …
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
CVE-2026-32475
Fetching description from NVD…
JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit
JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793
PoC of CVE-2023-42793
JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 POC
TeamCity CVE-2023-42793 exploit written in Rust
TeamCity RCE for Linux (CVE-2023-42793)
teamcity-exploit-cve-2023-42793
Windows & linux support
Fetching description from NVD…
gpgsm CVE-2026-57062 exploit POC
Fetching description from NVD…
CVE-2026-27771
Fetching description from NVD…
Fetching description from NVD…
Private research and validation for WebKitGTK file DnD restore (CVE-2025-13947 follow-up)
Fetching description from NVD…
PoC exploit code for CVE-2026-7873
Fetching description from NVD…
Security-research lab reproducing CVE-2026-39382 (GHSA-5jxf-vmqr-5g82): command injection in dbt-labs reusable workflow open-issue-in-repo.yml, driven by a dbt…
Fetching description from NVD…
Security-research lab: controlled reproduction of GHSA-3g6g-gq4r-xjm9 / CVE-2026-35580 (GitHub Actions workflow_dispatch input shell injection) against a pinne…
Fetching description from NVD…
Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml — snapshot of njz…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.