Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
358PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

CVE-2026-5027
MULTI PoC
PoCs 8 ★ 4 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 8 repositories
yahiahamza/CVE-2026-5027

CVE-2026-5027 - Langflow Path Traversal to Remote Code Execution (CVSS 8.8)

★ 4 · 2026-04-02
EQSTLab/CVE-2026-5027

Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal

★ 3 · 2026-04-24
yym8538/CVE-2026-5027
★ 1 · 2026-08-21
min8282/CVE-2026-5027

Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)

★ 0 · 2026-04-03
0xBlackash/CVE-2026-5027

CVE-2026-5027

★ 0 · 2026-04-03
Layer-6/CVE-2026-5027-Langflow
★ 0 · 2026-06-11
HORKimhab/CVE-2026-5027

CVE-2026-5027 - Draft

★ 0 · 2026-06-11
rmhowe425/POC-CVE-2026-5027

Proof of concept exploit code for CVE-2026-5027

★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
AndrielSec/CVE-2025-69080
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-d9fd584b12

Authorized security-research lab reproducing CVE-2024-47179 (GHSL-2024-178): artifact-poisoning pwn-request chain in RSSHub docker-test workflows (snapshot at …

★ 0 · 2026-09-02
PoCs 3 ★ 9 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 3 repositories
Nxploited/CVE-2026-1555

WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload

★ 9 · 2026-04-17
willygailo/WG-CVE-2026-1555-Linux
★ 0 · 2026-06-08
katranSefa/CVE-2026-1555
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
nabeelmkhan/CVE-2026-78839
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
nabeelmkhan/CVE-2026-78838
★ 0 · 2026-09-02
CVE-2022-25765
MULTI PoC
PoCs 10 ★ 31 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 8 of 10 repositories
UNICORDev/exploit-CVE-2022-25765

Exploit for CVE-2022–25765 (pdfkit) - Command Injection

★ 31 · 2025-09-12
PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell

pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ve…

★ 20 · 2022-12-06
shamo0/PDFkit-CMD-Injection

CVE-2022-25765 pdfkit <0.8.6 command injection.

★ 16 · 2022-12-21
nikn0laty/PDFkit-CMD-Injection-CVE-2022-25765

Exploit for CVE-2022-25765 command injection in pdfkit < 0.8.6

★ 10 · 2023-01-29
LordRNA/CVE-2022-25765

PoC for Blind RCE for CVE-2022-25765 (Tested in HTB - Precious Machine)

★ 3 · 2022-12-11
Wai-Yan-Kyaw/PDFKitExploit

A Shell exploit for CVE-2022-25765

★ 0 · 2022-11-29
lekosbelas/PDFkit-CMD-Injection

CVE-2022-25765 pdfkit 0.8.6 command injection.

★ 0 · 2023-02-22
lowercasenumbers/CVE-2022-25765

Exploit for CVE-2022-25765

★ 0 · 2025-11-19
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-7899

CVE-2026-7899 - Draft or TODO

★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-6ab39df295

Controlled security-research lab reproducing CVE-2024-45798 (GHSA-h52q-xhg2-6jw8) in espressif/arduino-esp32 — poisoned-artifact pwn request via tests_results.…

★ 0 · 2026-09-02
CVE-2026-9586
CRITICAL
CVSS 9.3 CRITICAL CWE-89 Published 2026-07-17 PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Show 1 repositories
HORKimhab/CVE-2026-9586

CVE-2026-9586 - Draft or TODO

★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Saku0512/CVE-2026-84361-poc
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
nabeelmkhan/CVE-2026-78837
★ 0 · 2026-09-02
CVE-2023-4863
HOTMULTI PoC
PoCs 14 ★ 319 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 8 of 14 repositories
mistymntncop/CVE-2023-4863
★ 319 · 2023-12-18
LiveOverflow/webp-CVE-2023-4863
★ 56 · 2024-05-13
caoweiquan322/NotEnough

This tool calculates tricky canonical huffman histogram for CVE-2023-4863.

★ 25 · 2023-12-20
murphysecurity/libwebp-checker

A tool for finding vulnerable libwebp(CVE-2023-4863)

★ 21 · 2023-10-07
bbaranoff/CVE-2023-4863
★ 6 · 2026-01-05
GTGalaxi/ElectronVulnerableVersion

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

★ 6 · 2023-10-01
OITApps/Find-VulnerableElectronVersion

Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129

★ 5 · 2023-09-29
huiwen-yayaya/CVE-2023-4863
★ 4 · 2024-06-08
PoCs 1 ★ 0 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-40e23db109

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in gradio-app/gradio @ …

★ 0 · 2026-09-02
CVE-2023-4357
HOTMULTI PoC
PoCs 7 ★ 230 Last push 2026-09-02 (1 month, 1 week ago)

Fetching description from NVD…

Show 7 repositories
xcanwin/CVE-2023-4357-Chrome-XXE

[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.

★ 230 · 2025-04-04
sunu11/chrome-CVE-2023-4357

poc

★ 4 · 2023-11-29
lon5948/CVE-2023-4357-Exploitation

Network Security Project

★ 4 · 2024-04-13
WinnieZy/CVE-2023-4357
★ 0 · 2024-01-09
CamillaFranceschini/CVE-2023-4357
★ 0 · 2024-06-20
shihongsu/NetSec-CVE-2023-4357
★ 0 · 2026-09-02
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
gabrielftanaka/CVE-2026-82221-PoC

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-ee08e207a8

Authorized security-research lab reproducing CVE-2024-4253 (GHSA-r897-wrpm-h4vw): workflow_run command injection in gradio-app/gradio's test-functional.yml

★ 0 · 2026-09-01
PoCs 2 ★ 2 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
Boreas37/CVE-2025-62593-PoC

PoC for CVE-2025-62593: unauthenticated RCE in Ray (CISA KEV). Stdlib-only Python.

★ 2 · 2026-08-18
maxprog-svg/CVE-2026-33017

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
christopher-leese/cve-2015-1187-dir820l-firmware-reverse-engineering

Independent reverse engineering and reproduction of CVE-2015-1187, an unauthenticated command injection in the D-Link DIR-820L (Rev A, v1.05B03). MIPS firmware…

★ 0 · 2026-09-01
CVE-2019-1388
HOTMULTI PoC
PoCs 6 ★ 193 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 6 repositories
jas502n/CVE-2019-1388

CVE-2019-1388 UAC提权 (nt authority\system)

★ 193 · 2019-11-21
sv3nbeast/CVE-2019-1388

guest→system(UAC手动提权)

★ 72 · 2020-03-18
nobodyatall648/CVE-2019-1388

CVE-2019-1388 Abuse UAC Windows Certificate Dialog

★ 20 · 2021-05-06
suprise4u/CVE-2019-1388
★ 7 · 2021-06-07
Tafloh/CVE-2019-1388-Privilege-Escalation--2021-

CVE-2019-1388 Lab Analysis: Documented local privilege escalation via Windows UAC certificate dialogs on Windows 7.

★ 1 · 2026-09-01
jaychouzzk/CVE-2019-1388
★ 0 · 2019-11-21
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
PoCs 2 ★ 1 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
LOURC0D3/CVE-2024-39700-PoC

CVE-2024-39700 Proof of Concept

★ 1 · 2024-07-31
pvharmo2/gha-lab-0ba60e6456

Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)

★ 0 · 2026-09-01
PoCs 1 ★ 3 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
HackSpeak/CVE-2026-82592

D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing

★ 3 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
cwjchoi01/CVE-2026-36130

CVE-2026-36130

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
cwjchoi01/CVE-2026-31321

CVE-2026-31321

★ 0 · 2026-09-01
< Prev Page 46 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.