Fetching description from NVD…
Show 1 repositories
Sliver HTTP(S) C2 PNG bomb DoS exploit — GHSA-663m-7x7m-g4fw (CVE-2026-77622)
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
Sliver HTTP(S) C2 PNG bomb DoS exploit — GHSA-663m-7x7m-g4fw (CVE-2026-77622)
Fetching description from NVD…
Poc CVE-2026-18080
Fetching description from NVD…
POC pre-auth RCE on Sharepoint chain
Fetching description from NVD…
CVE-2026-52618 — @webfer/mcp-ansible-drupal: OS command injection via executeDeployment extra vars (fixed in 2.0.3)
Fetching description from NVD…
CVE-2026-52617 — @sworddut/mcp-ffmpeg-helper: OS command injection via ffmpeg tool options (no fixed version)
Fetching description from NVD…
CVE-2026-52616 — mcp-nmap-server: OS command injection via run_nmap_scan (duplicate of CVE-2026-3484)
Fetching description from NVD…
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
Fetching description from NVD…
Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)
pgAdmin Proof of Concept
Exploit and test stand for CVE-2025-2945
Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes
Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.
PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9
Fetching description from NVD…
CVE-2026-63072
Fetching description from NVD…
Fetching description from NVD…
ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场
Fetching description from NVD…
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test inclu…
CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection
Fetching description from NVD…
5th RCE OS Command Injection on Data Input
Fetching description from NVD…
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y San…
Fetching description from NVD…
CVE-2026-35273
CVE-2026-35273
CVE-2026-35273 - Oracle PeopleSoft PeopleTools Unauthenticated RCE Scanner
Fetching description from NVD…
This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancil…
Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.
CVE-2026-68820 - Draft or TODO
CVE-2026-68820 — Mass Exploit Framework Edition.
Fetching description from NVD…
Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073
Fetching description from NVD…
OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.
CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing
Python poc, exploit for CVE-2025-69212
CVE-2025-69212 - OpenSTAManager OS Command Injection PoC
CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.
Fetching description from NVD…
Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.
Fetching description from NVD…
Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.
Fuel CMS 1.4.1 - Remote Code Execution
Fuel CMS 1.4.1 - Remote Code Execution
A working PoC to CVE-2018-16763
This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Executio…
Fetching description from NVD…
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC
CVE-2026-17532 Docker Lab.
Fetching description from NVD…
Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised …
Fetching description from NVD…
Fetching description from NVD…
CVE-2026-39154, Stored XSS in CometChat JS SDK
Fetching description from NVD…
CVE-2026-74970, Fission site isolation bypass in Firefox WebRender
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.