Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-84411
CVE-2026-108592
CVE-2026-107806
CVE-2026-106445
CVE-2026-104335
CVE-2026-103690
CVE-2026-102428
CVE-2025-9548
CVE-2025-69872
CVE-2025-20730
CVE-2021-42023
11 contacts in last 24h
11128CVEs tracked
26034PoC repositories
11New in 24h
358PoC updated in 7 days
filters
11128 results
PoCs 8
★ 4
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 repositories
EQSTLab/CVE-2026-5027
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal
★ 3 · 2026-04-24
min8282/CVE-2026-5027
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)
★ 0 · 2026-04-03
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
pvharmo2/gha-lab-d9fd584b12
Authorized security-research lab reproducing CVE-2024-47179 (GHSL-2024-178): artifact-poisoning pwn-request chain in RSSHub docker-test workflows (snapshot at …
★ 0 · 2026-09-02
PoCs 3
★ 9
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 3 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 10
★ 31
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 10 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
pvharmo2/gha-lab-6ab39df295
Controlled security-research lab reproducing CVE-2024-45798 (GHSA-h52q-xhg2-6jw8) in espressif/arduino-esp32 — poisoned-artifact pwn request via tests_results.…
★ 0 · 2026-09-02
CVSS 9.3 CRITICAL
CWE-89
Published 2026-07-17
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 14
★ 319
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 8 of 14 repositories
PoCs 1
★ 0
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
pvharmo2/gha-lab-40e23db109
Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in gradio-app/gradio @ …
★ 0 · 2026-09-02
PoCs 7
★ 230
Last push 2026-09-02 (1 month, 1 week ago)
Fetching description from NVD…
Show 7 repositories
xcanwin/CVE-2023-4357-Chrome-XXE
[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
★ 230 · 2025-04-04
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
pvharmo2/gha-lab-ee08e207a8
Authorized security-research lab reproducing CVE-2024-4253 (GHSA-r897-wrpm-h4vw): workflow_run command injection in gradio-app/gradio's test-functional.yml
★ 0 · 2026-09-01
PoCs 2
★ 2
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 2 repositories
maxprog-svg/CVE-2026-33017
CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.
★ 0 · 2026-09-01
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 6
★ 193
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 6 repositories
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 2
★ 1
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 2 repositories
pvharmo2/gha-lab-0ba60e6456
Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)
★ 0 · 2026-09-01
PoCs 1
★ 3
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
HackSpeak/CVE-2026-82592
D-Link DIR-825M formDiskFormat stack overflow + command injection RCE PoC (CVE-2026-82592); for authorized security testing
★ 3 · 2026-09-01
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-09-01 (1 month, 1 week ago)
Fetching description from NVD…
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.