Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
361PoC updated in 7 days
filters
11114 results
PoCs 7
★ 3
Last push 2026-10-09 (10 hours, 57 minutes ago)
Fetching description from NVD…
Show 7 repositories
joaomorenorf/CVE-2014-3704
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for M…
★ 1 · 2025-02-02
fbm31/Audit-BlackBox-Web-to-Root
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade ver…
★ 0 · 2025-12-31
PoCs 5
★ 124
Last push 2026-10-09 (10 hours, 57 minutes ago)
Fetching description from NVD…
Show 5 repositories
PoCs 5
★ 10
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 5 repositories
Darabium/couchdb-exploit
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Pr…
★ 0 · 2026-09-19
PoCs 2
★ 0
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 2 repositories
PoCs 37
★ 47
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 37 repositories
PoCs 95
★ 232
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 95 repositories
cj1324/CGIShell
shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI
★ 13 · 2014-10-02
CVSS 8.1 HIGH
CWE-287
Published 2018-03-15
PoCs 1
★ 0
Last push 2026-10-09 (10 hours, 58 minutes ago)
Discovered 2026-10-09 03:16
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Show 1 repositories
PoCs 2
★ 8
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 2 repositories
PoCs 13
★ 1073
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 13 repositories
1n7erface/PocList
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…
★ 1073 · 2023-05-11
j2ekim/CVE-2021-25646
Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646
★ 4 · 2021-12-12
PoCs 2
★ 1
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 2 repositories
PoCs 40
★ 126
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 40 repositories
Catherines77/ActiveMQ-EXPtools
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
★ 83 · 2026-06-27
PoCs 9
★ 83
Last push 2026-10-09 (10 hours, 58 minutes ago)
Fetching description from NVD…
Show 8 of 9 repositories
Catherines77/ActiveMQ-EXPtools
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
★ 83 · 2026-06-27
CVSS 8.1 HIGH
CWE-444
Published 2021-09-16
PoCs 1
★ 0
Last push 2026-10-09 (11 hours, 3 minutes ago)
Discovered 2026-10-09 03:16
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.
Show 1 repositories
PoCs 5
★ 130
Last push 2026-10-09 (12 hours, 9 minutes ago)
Fetching description from NVD…
Show 5 repositories
PoCs 51
★ 76
Last push 2026-10-09 (12 hours, 37 minutes ago)
Fetching description from NVD…
Show 8 of 51 repositories
ClickCyber/cve-2022-42889
cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text version 1.10.
★ 40 · 2022-10-18
PoCs 79
★ 788
Last push 2026-10-09 (14 hours, 28 minutes ago)
Fetching description from NVD…
Show 8 of 79 repositories
0xsha/wp2shell
CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core
★ 115 · 2026-07-18
dinosn/wp2shell-lab
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0…
★ 63 · 2026-07-22
NULL200OK/WP2Shell
WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, al…
★ 17 · 2026-07-18
47Cid/wp2shell-lab
Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion
★ 15 · 2026-07-18
CVSS 8.8 HIGH
CWE-416
Published 2026-09-25
PoCs 1
★ 2
Last push 2026-10-09 (14 hours, 49 minutes ago)
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.
Show 1 repositories
PoCs 14
★ 16
Last push 2026-10-09 (14 hours, 59 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
azilRababe/CVE-2026-46300
Technical analysis of CVE-2026-46300 (Fragnesia), a Linux kernel page-cache write vulnerability that enables local privilege escalation through SKBFL_SHARED_FR…
★ 2 · 2026-06-22
PoCs 3
★ 7
Last push 2026-10-09 (15 hours, 7 minutes ago)
Fetching description from NVD…
Show 3 repositories
Xewdy444/Netgrave
A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)
★ 7 · 2026-10-09
PoCs 68
★ 15
Last push 2026-10-09 (15 hours, 14 minutes ago)
Fetching description from NVD…
Show 8 of 68 repositories
PoCs 13
★ 150
Last push 2026-10-09 (15 hours, 50 minutes ago)
Fetching description from NVD…
Show 8 of 13 repositories
d0rb/CVE-2024-21762
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
★ 12 · 2024-03-17
deFr0ggy/CVE-2024-21762-Checker
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…
★ 0 · 2024-03-25
PoCs 12
★ 134
Last push 2026-10-09 (15 hours, 50 minutes ago)
Fetching description from NVD…
Show 8 of 12 repositories
PoCs 31
★ 358
Last push 2026-10-09 (15 hours, 50 minutes ago)
Fetching description from NVD…
Show 8 of 31 repositories
horizon3ai/CVE-2022-40684
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
★ 358 · 2022-10-13
PoCs 14
★ 253
Last push 2026-10-09 (15 hours, 50 minutes ago)
Fetching description from NVD…
Show 8 of 14 repositories
jpiechowka/at-doom-fortigate
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
★ 5 · 2024-01-23
PoCs 10
★ 73
Last push 2026-10-09 (16 hours, 19 minutes ago)
Fetching description from NVD…
Show 8 of 10 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.