Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
360PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Trachinus/CVE-2026-4813

PoC for CVE-2026-4813

★ 0 · 2026-09-03
PoCs 1 ★ 1 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Alardiians/gitea-CVE-2026-28699

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

★ 1 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-52810

CVE-2026-52810 - Draft or TODO

★ 0 · 2026-09-03
PoCs 2 ★ 5 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
ajdumanhug/CVE-2024-21546

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions and uploa…

★ 5 · 2025-05-05
digitalsurgn/CVE-2024-21546

This repository contains security assessment tooling, detection templates, and an automated exploit toolkit for identifying and exploiting Unauthenticated Remo…

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-78071

Stored XSS via Location Title in DPCalendar Free

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-78070

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
madebyrokit/CVE-2026-40976-POC
★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-59822

CVE-2026-59822 - Draft or TODO

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
CStockdale1/nextcloud-cve-2023-49792-research

A project analysis of CVE-2023-49792, inspired by a HackerOne report I have recently come across.

★ 0 · 2026-09-03
PoCs 2 ★ 3 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
yora1928/cve-2026-15748

CVE-2026-15748 - Unauthenticated RCE exploit for WordPress Forminator plugin (≤1.56.1). Automated detection, deep crawl, nonce extraction, and safe upload test…

★ 3 · 2026-09-03
ubaydev/CVE-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

★ 0 · 2026-08-19
PoCs 1 ★ 0 Last push 2026-09-03 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-becf103a54

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration workflow artif…

★ 0 · 2026-09-03
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 2 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
redr0nin/CVE-2026-63563

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers

★ 2 · 2026-09-02
PoCs 1 ★ 1 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
typedefabcd1234ntd/CVE-2026-13753-poc

Poc of CVE-2026-13753

★ 1 · 2026-09-02
PoCs 2 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
HORKimhab/CVE-2026-0768

CVE-2026-0768 - Draft or TODO

★ 0 · 2026-09-01
rmhowe425/POC-CVE-2026-0768

Proof of concept exploit code for CVE-2026-0768

★ 0 · 2026-09-02
CVSS 6.5 MEDIUM CWE-22 Published 2026-08-02 PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpers, which are designed to reject ExternalLinks and SoftLinks. This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem. Specifically, `KerasFileEditor` extracts attributes and datasets from linked files into its internal structures, while `keras.saving.load_weights` loads weights from linked files into the user's model. This issue can be exploited by providing a malicious `.h5`, `.weights.h5`, or `.keras` file containing ExternalLinks.

Show 1 repositories
paparojonathan/CVE-2026-9335-keras-hdf5-externallink

CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory + verified…

★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
poxsky/CVE-2026-38577

CVE-2026-38577

★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-23db52563c

Security-research lab: reproduction of CVE-2025-10894 (PR-title injection in GitHub Actions) — snapshot of nrwl/nx

★ 0 · 2026-09-02
CVE-2026-9055
CRITICAL
CVSS 9.8 CRITICAL CWE-269 Published 2026-09-02 PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when the 'externalId' parameter is set to 0. This makes it possible for unauthenticated attackers to escalate their privileges to administrator by first elevating to the manager role, then creating a provider entity linked to an administrator user ID and overwriting that administrator's password.

Show 1 repositories
EXEcution-py/CVE-2026-9055
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
0xBlackash/CVE-2026-73296

CVE-2026-73296

★ 0 · 2026-09-02
PoCs 1 ★ 3 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
AneKazek/cve-2026-47627
★ 3 · 2026-09-02
CVE-2026-9198
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-94 Published 2026-07-17 PoCs 8 ★ 3 Last push 2026-09-02 (1 month, 1 week ago)

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

Show 8 repositories
0xgh057r3c0n/CVE-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

★ 3 · 2026-07-24
0xdak/CVE-2026-9198_exploit
★ 1 · 2026-07-21
rmhowe425/PoC-CVE-2026-9198

Proof of concept exploit code for CVE-2026-9198

★ 1 · 2026-09-02
ywh-jfellus/CVE-2026-9198

Proof of Concept for CVE-2026-9198 - IBM Langflow Unauthenticated RCE via Auto-Login Bypass

★ 0 · 2026-07-24
Procjevt/CVE-2026-9198
★ 0 · 2026-08-10
CuteeCat/CVE-2026-9198

CVE-2026-9198利用代码

★ 0 · 2026-08-11
chessalekin/cve-2026-9198_exploit
★ 0 · 2026-08-24
joaovicdev/EXPLOIT-CVE-2026-9198
★ 0 · 2026-08-29
CVE-2026-0920
MULTI PoC
PoCs 5 ★ 7 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 5 repositories
John-doe-code-a11/CVE-2026-0920

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

★ 7 · 2026-01-28
Nxploited/CVE-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole parameter

★ 3 · 2026-04-18
Dx3iZ/CVE-2026-0920

Creating a Wordpress Admin User

★ 0 · 2026-07-06
katranSefa/CVE-2026-0920
★ 0 · 2026-09-02
CVE-2025-6440
MULTI PoC
PoCs 8 ★ 1 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 8 repositories
AnotherSec/CVE-2025-6440

WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload

★ 1 · 2025-12-01
Nxploited/CVE-2025-6440

WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Upload

★ 1 · 2025-11-10
m2hcz/CVE-2025-6440-Poc-Exploit
★ 1 · 2026-07-18
sahmsec/CVE-2025-6440

CVE-2025-6440

★ 1 · 2026-05-07
rimbadirgantara/CVE-2025-6440

nuclei tamplate to CVE-2025-6440

★ 0 · 2026-01-03
0axz-tools/CVE-2025-6440
★ 0 · 2026-03-08
SangSenimanWartefak/CVE-2025-6440
★ 0 · 2026-06-11
katranSefa/CVE-2025-6440
★ 0 · 2026-09-02
PoCs 3 ★ 1 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 3 repositories
Nxploited/CVE-2025-29009

WordPress Medical Prescription Attachment Plugin for WooCommerce Plugin <= 1.2.3 is vulnerable to a high priority Arbitrary File Upload

★ 1 · 2026-04-18
jsecx88/CVE-2025-29009-POC

Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Unauthenticated Arbitrary File Upload.

★ 0 · 2025-11-04
katranSefa/CVE-2025-29009
★ 0 · 2026-09-02
< Prev Page 45 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.