Fetching description from NVD…
Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
Show 2 repositories
One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE
PostGIS SQL Injection GeoTools
Fetching description from NVD…
Show 1 repositories
Fetching description from NVD…
Show 7 repositories
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
exploit for cve-2025-43529
A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the …
CVE-2025-43529 Test
Fetching description from NVD…
Show 2 repositories
UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.
CVE-2026-28992 IOHIDFamily FastPathUserClient race condition PoC — security research
Fetching description from NVD…
Show 2 repositories
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)
Fetching description from NVD…
Show 2 repositories
CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)
CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)
Fetching description from NVD…
Show 3 repositories
NGINX `ngx_http_dav_module` Heap Buffer Overflow via `size_t` Underflow (Remote DoS / Potential RCE)
Proof-of-Concept and technical analysis for CVE-2026-27654, a heap-based buffer overflow vulnerability in the NGINX HTTP WebDAV module, including root cause an…
Обзор n-day уязвимости на русском языке.
Fetching description from NVD…
Show 1 repositories
For educational purposes
Fetching description from NVD…
Show 2 repositories
Unauthenticated RCE exploit for Veritas Backup Exec Agent (CVE-2021-27876/77/78) — SHA auth bypass to SYSTEM via NDMP
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
Fetching description from NVD…
Show 1 repositories
Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification rec…
Fetching description from NVD…
Show 5 repositories
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedd…
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists of embedde…
Python tool for CVE-2010-1240 research - generates malicious PDFs exploiting Adobe Reader Launch Actions
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-12…
Fetching description from NVD…
Show 6 repositories
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068, and CVE-20…
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning
Fetching description from NVD…
Show 1 repositories
CVE-2015-3246
Fetching description from NVD…
Show 1 repositories
CVE-2015-5287
Fetching description from NVD…
Show 5 repositories
CVE-2026-19478 PoC . Unauthenticated remote code-injection in GitLab's GraphQL layer
Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)
GitLab Code injection
Nuclei detection template for CVE-2026-19478, a critical (CVSS 9.4) unauthenticated arbitrary method invocation flaw in the GitLab GraphQL API,
CVE-2026-19478: GitLab GraphQL Vulnerability PoC
Fetching description from NVD…
Show 1 repositories
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
Fetching description from NVD…
Show 1 repositories
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
Fetching description from NVD…
Show 1 repositories
CVE-2026-18431 - Draft or TODO
Fetching description from NVD…
Show 3 repositories
0 Click RCE exploit for CVE-2026-34159 Lama.cpp RPC server
Critical buffer validation bypass in deserialize_tensor() (llama.cpp < b8492). Null tensor buffer skips bounds check, enabling unauthenticated arbitrary R/W vi…
CVE-2026-34159 PoC and exploit
Fetching description from NVD…
Show 1 repositories
CVE-2026-8467 - Draft or TODO
Fetching description from NVD…
Show 1 repositories
Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.
Fetching description from NVD…
Show 1 repositories
Fetching description from NVD…
Show 3 repositories
Python script to exploit CVE-2022-29303
Python script to exploit CVE-2022-29303
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
Fetching description from NVD…
Show 1 repositories
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.