Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
357PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 2 ★ 5 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 2 repositories
Nxploited/CVE-2025-39401

WordPress WPAMS Plugin <= 44.0 (17-08-2023) is vulnerable to a high priority Arbitrary File Upload

★ 5 · 2025-11-27
katranSefa/CVE-2025-39401
★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Trachinus/CVE-2026-27472-and-CVE-2026-27474

PoC for CVE-2026-27472 and CVE-2026-27474

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Kihara-1/postgresql-cve-2026-14662

PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Trachinus/CVE-2026-27475

PoC for CVE-2026-27475

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pervinzahidli/CVE-2026-75855

ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing auth…

★ 0 · 2026-09-01
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
CVE-2021-3493
HOTMULTI PoC
PoCs 20 ★ 442 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 8 of 20 repositories
briskets/CVE-2021-3493

Ubuntu OverlayFS Local Privesc

★ 442 · 2024-04-02
inspiringz/CVE-2021-3493

CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)

★ 42 · 2021-07-07
oneoy/CVE-2021-3493
★ 3 · 2021-04-22
puckiestyle/CVE-2021-3493
★ 2 · 2021-10-02
Ayham-Megdadi/Zero-Day-Legacy

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hi…

★ 2 · 2026-07-05
cerodah/overlayFS-CVE-2021-3493

2021 kernel vulnerability in Ubuntu.

★ 1 · 2021-09-12
fei9747/CVE-2021-3493
★ 1 · 2022-11-29
Abdennour-py/CVE-2021-3493
★ 0 · 2021-05-02
PoCs 1 ★ 0 Last push 2026-09-01 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-8e9316151c

Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot …

★ 0 · 2026-09-01
CVE-2018-14667
MULTI PoC
PoCs 7 ★ 50 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 7 repositories
syriusbughunt/CVE-2018-14667

All about CVE-2018-14667; From what it is to how to successfully exploit it.

★ 50 · 2018-11-30
Venscor/CVE-2018-14667-poc

CVE-2018-14667-poc Richfaces漏洞环境及PoC

★ 8 · 2019-09-24
zeroto01/CVE-2018-14667
★ 2 · 2018-11-23
r00t4dm/CVE-2018-14667

about CVE-2018-14667 from RichFaces Framework 3.3.4

★ 1 · 2018-11-29
quandqn/cve-2018-14667
★ 1 · 2019-07-29
nareshmail/cve-2018-14667

cve-2018-14667 demo

★ 0 · 2018-11-17
r4ch1d0/CVE-2018-14667_Lab_POC

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-6255f5fc33

Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
vEnablee/CVE-2026-30252

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password fun…

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
vEnablee/CVE-2026-30251

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to exe…

★ 0 · 2026-08-31
PoCs 3 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 3 repositories
ChoDeokCheol/CVE-2023-39361
★ 0 · 2025-04-26
PoCs 3 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 3 repositories
curtishoughton/Cisco-ASA-CVE-2025-20333-Scanner

Safe Python scanner for Cisco CVE-2025-20333 (Cisco ASA/FTD WebVPN Buffer Overflow)

★ 0 · 2026-05-16
cobbbex/Cisco-ASA-vulnerability-research

Cisco ASA vulnerability research CVE-2025-20333/CVE-2025-20362

★ 0 · 2026-08-22
cobbbex/cve-2025-20333
★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
boomerangBS/CVE-2026-65647-PoC
★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
brendonlee20042004-sys/weakrng-sweep

Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
CharanMv08/cve-2022-29117-assessment

CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (sn…

★ 0 · 2026-08-31
CVE-2025-66034
MULTI PoC
PoCs 6 ★ 4 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 6 repositories
v3cn4x00/POC-CVE-2025-66034
★ 4 · 2026-03-21
symphony2colour/varlib-cve-2025-66034

Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, …

★ 2 · 2026-08-31
tristanqtn/CVE-2025-66034

CVE-2025-66034 exploit and documentation

★ 1 · 2026-03-29
jwsly12/CVE-2025-66034-htb-ctf
★ 1 · 2026-04-07
4nuxd/CVE-2025-66034

CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.

★ 0 · 2026-03-28
CVE-2015-5254
MULTI PoC
PoCs 5 ★ 83 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 5 repositories
Catherines77/ActiveMQ-EXPtools

Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)

★ 83 · 2026-06-27
jas502n/CVE-2015-5254

ActiveMQ Deserialization RCE

★ 15 · 2019-08-30
Ma1Dong/ActiveMQ_CVE-2015-5254

ActiveMQ_CVE-2015-5254

★ 2 · 2020-08-03
guigui237/Exploitation-de-la-vuln-rabilit-CVE-2015-5254-

La vulnérabilité CVE-2015-5254 est une faille de sécurité dans Apache ActiveMQ, un serveur de messages open source largement utilisé pour la communication entr…

★ 0 · 2024-11-05
radsih/activemq-cve-lab

ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
bsdrip/CVE-2026-40179-PoC

A minimal, dependency-light proof of concept for CVE-2026-40179 (GHSA-vffh-x6r8-xx99): stored cross-site scripting in the Prometheus web UI, delivered through …

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

★ 0 · 2026-08-31
PoCs 1 ★ 39 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
canyie/TransitionPlayer

CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb

★ 39 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
pvharmo2/gha-lab-b9842b12c0

Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment

★ 0 · 2026-08-31
PoCs 1 ★ 0 Last push 2026-08-31 (1 month, 1 week ago)

Fetching description from NVD…

Show 1 repositories
Hari-v542/CVE-2026-52923
★ 0 · 2026-08-31
< Prev Page 47 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.