Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
354PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
defineid/Palimpsest

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

★ 0 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
defineid/SkeletonKey

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

★ 0 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
defineid/Revenant

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

★ 0 · 2026-08-25
PoCs 1 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
finnvle/CVE-2022-28906-POC

CVE-2022-28906 Proof of concept in Python3

★ 1 · 2026-08-25
CVE-2022-42475
HOTMULTI PoC
PoCs 9 ★ 108 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 9 repositories
scrt/cve-2022-42475

POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon

★ 108 · 2023-03-14
0xhaggis/CVE-2022-42475

An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products

★ 33 · 2023-06-21
P4x1s/CVE-2022-42475-RCE-POC

CVE-2022-42475 飞塔RCE漏洞 POC

★ 8 · 2023-03-23
Amir-hy/cve-2022-42475

FortiOS buffer overflow vulnerability

★ 7 · 2023-03-16
bryanster/ioc-cve-2022-42475

test for the ioc described for FG-IR-22-398

★ 1 · 2023-05-14
uLl0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the S…

★ 1 · 2026-08-25
natceil/cve-2022-42475
★ 0 · 2023-04-27
PoCs 1 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
selecthch/CVE-2026-41551

ROS# 路径遍历漏洞(CVE-2026-41551)

★ 1 · 2026-08-25
PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Slagzz/CVE-2026-16348

TP-Link Archer BE800 V1 — VPN Key Injection RCE

★ 0 · 2026-08-25
PoCs 1 ★ 2 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
tony102741/CVE-2026-15469

CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).

★ 2 · 2026-08-25
CVSS 8.7 HIGH CWE-78 Published 2026-08-24 PoCs 1 ★ 0 Last push 2026-08-25 (1 month, 2 weeks ago)

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

Show 1 repositories
Slagzz/CVE-2026-9254

TP-Link Archer BE800 V1 — Parental Control LAN RCE

★ 0 · 2026-08-25
PoCs 1 ★ 1 Last push 2026-08-25 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
SneakyNachos/CVE-2026-12295-UXXS-in-my-wasm

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim …

★ 1 · 2026-08-25
PoCs 1 ★ 2 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
CuteeCat/CVE-2026-77806

CVE-2026-77806漏洞检测代码

★ 2 · 2026-08-24
PoCs 1 ★ 1 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
SneakyNachos/CVE-2026-74939-escape-the-mac-n-cheese-box

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement,…

★ 1 · 2026-08-24
CVE-2026-50522
MULTI PoC
PoCs 5 ★ 43 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 5 repositories
4minx/CVE-2026-50522

CVE-2026-50522 PoC

★ 43 · 2026-08-15
WismanSec/sharepoint-2026-poc

PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering unauthenticated RCE,…

★ 2 · 2026-08-06
HORKimhab/CVE-2026-50522

CVE-2026-50522

★ 0 · 2026-08-24
ChPratik/CVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

★ 0 · 2026-07-27
darses/CVE-2026-50522

Microsoft SharePoint CVE-2026-50522

★ 0 · 2026-07-30
PoCs 1 ★ 1 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Boreas37/CVE-2026-43914-PoC

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

★ 1 · 2026-08-24
CVE-2019-0708
HOTMULTI PoC
PoCs 122 ★ 1185 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 122 repositories
Ekultek/BlueKeep

Proof of concept for CVE-2019-0708

★ 1185 · 2026-03-16
robertdavidgraham/rdpscan

A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.

★ 921 · 2019-06-22
n1xbyte/CVE-2019-0708

dump

★ 494 · 2019-06-01
k8gege/CVE-2019-0708

3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)

★ 389 · 2019-06-13
algo7/bluekeep_CVE-2019-0708_poc_to_exploit

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

★ 342 · 2021-01-10
cbwang505/CVE-2019-0708-EXP-Windows

CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell

★ 317 · 2020-01-21
0xeb-bp/bluekeep

Public work for CVE-2019-0708

★ 294 · 2019-11-19
Cyb0r9/ispy

ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )

★ 244 · 2021-02-06
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
samarthop2011/PoC-for-CVE-2025-46359

PoC CVE-2025-46359

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-63039

Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-28672

Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-78329

Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-71300

Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-60093

Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-66906

Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus

★ 0 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-66907

Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus

★ 0 · 2026-08-24
PoCs 1 ★ 3 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
alicealys/mgo3-rce

CVE-2026-19874

★ 3 · 2026-08-24
PoCs 1 ★ 0 Last push 2026-08-24 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oscerd/CVE-2026-66908

Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main

★ 0 · 2026-08-24
< Prev Page 52 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.