Fetching description from NVD…
Show 2 repositories
WordPress WPAMS Plugin <= 44.0 (17-08-2023) is vulnerable to a high priority Arbitrary File Upload
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
WordPress WPAMS Plugin <= 44.0 (17-08-2023) is vulnerable to a high priority Arbitrary File Upload
Fetching description from NVD…
PoC for CVE-2026-27472 and CVE-2026-27474
Fetching description from NVD…
PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料
Fetching description from NVD…
PoC for CVE-2026-27475
Fetching description from NVD…
ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, allowing auth…
Fetching description from NVD…
Fetching description from NVD…
Ubuntu OverlayFS Local Privesc
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hi…
2021 kernel vulnerability in Ubuntu.
Fetching description from NVD…
Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot …
Fetching description from NVD…
All about CVE-2018-14667; From what it is to how to successfully exploit it.
CVE-2018-14667-poc Richfaces漏洞环境及PoC
about CVE-2018-14667 from RichFaces Framework 3.3.4
cve-2018-14667 demo
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server
Fetching description from NVD…
Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml
Fetching description from NVD…
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password fun…
Fetching description from NVD…
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to exe…
Fetching description from NVD…
Fetching description from NVD…
Safe Python scanner for Cisco CVE-2025-20333 (Cisco ASA/FTD WebVPN Buffer Overflow)
Cisco ASA vulnerability research CVE-2025-20333/CVE-2025-20362
Fetching description from NVD…
Fetching description from NVD…
Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership
Fetching description from NVD…
CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework
Fetching description from NVD…
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (sn…
Fetching description from NVD…
Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, …
CVE-2025-66034 exploit and documentation
CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.
Fetching description from NVD…
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
ActiveMQ Deserialization RCE
ActiveMQ_CVE-2015-5254
La vulnérabilité CVE-2015-5254 est une faille de sécurité dans Apache ActiveMQ, un serveur de messages open source largement utilisé pour la communication entr…
ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示
Fetching description from NVD…
A minimal, dependency-light proof of concept for CVE-2026-40179 (GHSA-vffh-x6r8-xx99): stored cross-site scripting in the Prometheus web UI, delivered through …
Fetching description from NVD…
Reflected XSS via search GET Parameter in Phoca Download
Fetching description from NVD…
CVE-2026-0091, play with an issue in android window management to perform arbitrary code execution in Launcher process from adb
Fetching description from NVD…
Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment
Fetching description from NVD…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.