Fetching description from NVD…
Show 1 repositories
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11128 results
Fetching description from NVD…
CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)
Fetching description from NVD…
CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox
Fetching description from NVD…
CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)
Fetching description from NVD…
CVE-2022-28906 Proof of concept in Python3
Fetching description from NVD…
POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475 飞塔RCE漏洞 POC
FortiOS buffer overflow vulnerability
test for the ioc described for FG-IR-22-398
Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the S…
Fetching description from NVD…
ROS# 路径遍历漏洞(CVE-2026-41551)
Fetching description from NVD…
TP-Link Archer BE800 V1 — VPN Key Injection RCE
Fetching description from NVD…
CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
TP-Link Archer BE800 V1 — Parental Control LAN RCE
Fetching description from NVD…
Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim …
Fetching description from NVD…
CVE-2026-77806漏洞检测代码
Fetching description from NVD…
Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement,…
Fetching description from NVD…
CVE-2026-50522 PoC
PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE,…
CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint CVE-2026-50522
Fetching description from NVD…
PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.
Fetching description from NVD…
Proof of concept for CVE-2019-0708
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
Public work for CVE-2019-0708
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
Fetching description from NVD…
PoC CVE-2025-46359
Fetching description from NVD…
Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)
Fetching description from NVD…
Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)
Fetching description from NVD…
Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot
Fetching description from NVD…
Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot
Fetching description from NVD…
Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus
Fetching description from NVD…
Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus
Fetching description from NVD…
Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus
Fetching description from NVD…
CVE-2026-19874
Fetching description from NVD…
Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.