Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
354PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 1 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Squ1shification/PNGboomer-CVE-2026-77622

Sliver HTTP(S) C2 PNG bomb DoS exploit — GHSA-663m-7x7m-g4fw (CVE-2026-77622)

★ 1 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Polosss/By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

★ 0 · 2026-08-26
PoCs 1 ★ 1 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
hypnguyen1209/CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

★ 1 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
s1ko/CVE-2026-52618

CVE-2026-52618 — @webfer/mcp-ansible-drupal: OS command injection via executeDeployment extra vars (fixed in 2.0.3)

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
s1ko/CVE-2026-52617

CVE-2026-52617 — @sworddut/mcp-ffmpeg-helper: OS command injection via ffmpeg tool options (no fixed version)

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
s1ko/CVE-2026-52616

CVE-2026-52616 — mcp-nmap-server: OS command injection via run_nmap_scan (duplicate of CVE-2026-3484)

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
HORKimhab/CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

★ 0 · 2026-08-26
CVE-2025-2945
MULTI PoC
PoCs 7 ★ 7 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
Cycloctane/cve-2025-2945-poc

Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)

★ 7 · 2025-11-30
abrewer251/CVE-2025-2945_PgAdmin_PoC

pgAdmin Proof of Concept

★ 3 · 2025-06-03
I3r1h0n/pgAdminOpendoor

Exploit and test stand for CVE-2025-2945

★ 0 · 2025-11-11
plur1bu5/CVE-2025-2945-pgadmin-rce

Authenticated RCE in pgAdmin 4 (8.10–9.1) via eval() injection in the Query Tool. This is an updated PoC with compatibility fixes for pgAdmin 9.x auth changes

★ 0 · 2026-03-16
g0d150ne/CVE-2025-2945

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

★ 0 · 2026-08-10
Khashayarnzk/CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
0xBlackash/CVE-2026-63072

CVE-2026-63072

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
mohamedjawady/CVE-2026-53613-poc
★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
ehaoxiongdiycw/CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

★ 0 · 2026-08-26
PoCs 2 ★ 2 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
Boreas37/CVE-2026-56705

CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test inclu…

★ 2 · 2026-08-25
ChiefYoru/Exploit-CVE-2026-56705

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-26 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
kx00007/CVE-2026-39902

5th RCE OS Command Injection on Data Input

★ 0 · 2026-08-26
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
fevar54/CVE-2026-72530-TrueConf-Sandbox-Escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y San…

★ 0 · 2026-08-25
PoCs 3 ★ 4 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 3 repositories
HORKimhab/CVE-2026-35273

CVE-2026-35273

★ 4 · 2026-08-25
0xBlackash/CVE-2026-35273

CVE-2026-35273

★ 3 · 2026-06-12
12hrformat/CVE-2026-35273-POC

CVE-2026-35273 - Oracle PeopleSoft PeopleTools Unauthenticated RCE Scanner

★ 1 · 2026-06-26
PoCs 4 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 4 repositories
ubitquity/Windows-WinSock-UAF-Mitigation

This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancil…

★ 1 · 2026-08-15
fevar54/CVE-2026-68820-Mitigation-PoC-

Demostracion educativa de mitigacion de CVE-2026-68820: Use-After-Free en afd.sys de Windows.

★ 1 · 2026-08-24
HORKimhab/CVE-2026-68820

CVE-2026-68820 - Draft or TODO

★ 0 · 2026-08-13
maxprog-svg/CVE-2026-68820_Mass_Exploit

CVE-2026-68820 — Mass Exploit Framework Edition.

★ 0 · 2026-08-25
PoCs 1 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
BishopFox/CVE-2026-58073-check

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

★ 1 · 2026-08-25
CVE-2025-69212
MULTI PoC
PoCs 13 ★ 5 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 13 repositories
BridgerAlderson/CVE-2025-69212-PoC

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

★ 5 · 2026-07-02
lukasz-rybak/CVE-2025-69212

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

★ 4 · 2026-04-11
tohib09/CVE-2025-69212-PoC
★ 4 · 2026-06-28
c0gnit00/CVE-2026-69212

Python poc, exploit for CVE-2025-69212

★ 2 · 2026-06-28
w3nch/CVE-2025-69212
★ 1 · 2026-06-29
xorandd/CVE-2025-69212-PoC
★ 0 · 2026-07-07
alaeddine03/CVE-2025-69212-PoC

CVE-2025-69212 - OpenSTAManager OS Command Injection PoC

★ 0 · 2026-07-01
m2sousa/CVE-2025-69212

CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.

★ 0 · 2026-07-01
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
fevar54/CVE-2026-32635-Angular-XSS-Mitigation-

Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.

★ 0 · 2026-08-25
CVE-2018-16763
MULTI PoC
PoCs 24 ★ 27 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 24 repositories
p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

★ 27 · 2025-01-31
padsalatushal/CVE-2018-16763

Fuel CMS 1.4.1 - Remote Code Execution

★ 6 · 2021-11-13
altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE

Fuel CMS 1.4.1 - Remote Code Execution

★ 5 · 2025-01-08
shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--

A working PoC to CVE-2018-16763

★ 3 · 2021-03-07
hikarihacks/CVE-2018-16763-exploit

This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1

★ 2 · 2020-09-03
kxisxr/Bash-Script-CVE-2018-16763

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Executio…

★ 2 · 2021-11-30
h3x0v3rl0rd/CVE-2018-16763
★ 2 · 2025-06-05
PoCs 2 ★ 2 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
kalhoralireza/CVE-2026-17532

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

★ 2 · 2026-08-05
kalhoralireza/CVE-2026-17532-lab

CVE-2026-17532 Docker Lab.

★ 0 · 2026-08-25
PoCs 1 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
SneakyNachos/CVE-2026-4692-trust-me-im-in-rdm

Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised …

★ 1 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Blinky-Keys/CVE-2026-48060
★ 0 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
defineid/Wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

★ 0 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
defineid/Trespasser

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

★ 0 · 2026-08-25
< Prev Page 51 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.