Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11128CVEs tracked
26034PoC repositories
11New in 24h
354PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11128 results

CVE-2021-36260
HOTMULTI PoC
PoCs 14 ★ 389 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 of 14 repositories
tamim1089/HikvisionExploiter

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the W…

★ 389 · 2025-12-22
Aiminsun/CVE-2021-36260

command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability t…

★ 305 · 2021-10-28
Cuerz/CVE-2021-36260

海康威视RCE漏洞 批量检测和利用工具

★ 171 · 2022-08-05
TaroballzChen/CVE-2021-36260-metasploit

the metasploit script(POC) about CVE-2021-36260

★ 20 · 2021-11-03
rabbitsafe/CVE-2021-36260

CVE-2021-36260

★ 17 · 2023-10-27
tuntin9x/CheckHKRCE

CVE-2021-36260

★ 7 · 2022-10-27
sylhetyhackvenger/HIKRAVEN

HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests de…

★ 7 · 2026-08-22
aengussong/hikvision_probe

Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)

★ 3 · 2024-11-26
PoCs 2 ★ 14 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
Boreas37/CVE-2026-34910-PoC

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

★ 14 · 2026-08-21
gagaltotal/CVE-2026-34910-unifi-poc

CVE-2026-34910 - CVE-2026-34909 Unifi OS

★ 0 · 2026-08-22
PoCs 1 ★ 3 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
oiehnow/oieh-router-checker

내 공유기가 Zbtlink ENDLESSDOORS 백도어(CVE-2026-66747) 대상인지 클릭 한 번으로 검사하는 Windows 프로그램

★ 3 · 2026-08-22
PoCs 1 ★ 0 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
daehyuh/CVE-2026-47883

CVE-2026-47883 PoC

★ 0 · 2026-08-22
PoCs 1 ★ 0 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Haomin-Yu/cve-2024-13176-timing-analysis

Instrumented analysis and reproducibility materials for ECDSA timing leakage in OpenSSL CVE-2024-13176

★ 0 · 2026-08-22
PoCs 1 ★ 0 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-74252

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

★ 0 · 2026-08-22
CVE-2026-0740
MULTI PoC
PoCs 8 ★ 24 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 8 repositories
0xgh057r3c0n/CVE-2026-0740

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload

★ 24 · 2026-07-18
xShadow-Here/CVE-2026-0740

POC

★ 3 · 2026-04-08
MadExploits/ninja-form-exploit

CVE-2026-0740

★ 3 · 2026-07-14
whattheslime/CVE-2026-0740

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)

★ 2 · 2026-06-12
murrez/CVE-2026-0740

CVE-2026-0740

★ 1 · 2026-04-25
ExDev994/CVE-2026-0740-mass

PoC untuk CVE-2026-0740: Ninja Forms File Uploads <= 3.3.26 — Unauthenticated Arbitrary File Upload yang dapat mengarah ke RCE.

★ 1 · 2026-07-11
a24ac1/CVE-2026-0740
★ 0 · 2026-05-20
PoCs 1 ★ 26 Last push 2026-08-22 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
endrazine/lean-cve-poc

CVE-2026-72844 : Example of proving "0 = 1" using a vulnerability in the Lean 4 kernel.

★ 26 · 2026-08-22
PoCs 2 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
sentinel-aidefense/CVE-2026-69836-EXP

CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization

★ 1 · 2026-08-21
HORKimhab/CVE-2026-69836

CVE-2026-69836 - Draft or TODO

★ 0 · 2026-08-21
CVE-2026-26980
MULTI PoC
PoCs 7 ★ 19 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 7 repositories
dinosn/ghost-cve-2026-26980

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

★ 19 · 2026-04-18
gagaltotal/CVE-2026-26980-Ghost-CMS-Api

CVE-2026-26980 - Ghost CMS Content API SQL Injection

★ 11 · 2026-06-26
vognik/CVE-2026-26980

💣 Exploit for CVE-2026-26980 — 👻 Ghost CMS Unauthenticated SQLi via Content API

★ 10 · 2026-08-16
EQSTLab/CVE-2026-26980

Ghost Content API SQL Injection

★ 3 · 2026-05-27
n0bitaemon/CVE-2026-26980-PoC

Ghost CMS Content API Blind SQL Injection

★ 1 · 2026-06-26
yym8538/CVE-2026-26980
★ 1 · 2026-08-21
Kulik-Labs-Development/Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass clear and ed…

★ 0 · 2026-08-21
PoCs 1 ★ 0 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
murrez/CVE-J2store-2026

PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)

★ 0 · 2026-08-21
PoCs 1 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Boreas37/CVE-2026-58455-PoC

PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

★ 1 · 2026-08-21
PoCs 1 ★ 0 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-76564

Stored XSS via User-Agent in Admin Order View in PhocaCart

★ 0 · 2026-08-21
PoCs 1 ★ 0 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
toanln-cov/CVE-2026-76565

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

★ 0 · 2026-08-21
PoCs 1 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
PoCs 1 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Boreas37/CVE-2026-64824-PoC

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py overwrite).…

★ 1 · 2026-08-21
PoCs 1 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
Boreas37/CVE-2026-69084-PoC

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

★ 1 · 2026-08-21
PoCs 1 ★ 0 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
berdav/CVE-2026-41567

CVE-2026-41567 1day

★ 0 · 2026-08-21
PoCs 1 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
gui-ying233/CVE-2025-61638

CVE-2025-61638 PoC

★ 1 · 2026-08-21
CVE-2026-2005
MULTI PoC
PoCs 5 ★ 27 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 5 repositories
var77/CVE-2026-2005

PoC for CVE-2026-2005

★ 27 · 2026-05-13
dinosn/cve-2026-2005

CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit

★ 18 · 2026-05-05
M3str3/CVE-2026-2005

PoC for CVE-2026-2005 — heap buffer overflow in PostgreSQL pgcrypto (pgp_pub_decrypt). Oversized PGP session key bypasses bounds check in pgp-pubdec.c. Affects…

★ 0 · 2026-03-07
stvm8/CVE-2026-2005_lab
★ 0 · 2026-05-04
open-flaw/CVE-2026-2005
★ 0 · 2026-08-21
PoCs 1 ★ 0 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 1 repositories
20000419/CVE-2026-39113

CVE-2026-39113: SQLite SQLAR heap-buffer-overflow advisory and reproducer

★ 0 · 2026-08-21
PoCs 2 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
EQSTLab/CVE-2026-30951

Sequelize JSON Cast SQL Injection

★ 1 · 2026-08-19
yym8538/CVE-2026-30951
★ 1 · 2026-08-21
PoCs 2 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
EQSTLab/CVE-2026-34220

SQL Injection vulnerability in MikroORM

★ 1 · 2026-08-19
yym8538/CVE-2026-34220
★ 1 · 2026-08-21
PoCs 2 ★ 1 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
EQSTLab/CVE-2026-0603

Hibernate ORM Second-Order SQL Injection

★ 1 · 2026-08-19
yym8538/CVE-2026-0603
★ 1 · 2026-08-21
PoCs 2 ★ 2 Last push 2026-08-21 (1 month, 2 weeks ago)

Fetching description from NVD…

Show 2 repositories
EQSTLab/CVE-2026-40897

Math.js Expression Parser RCE

★ 2 · 2026-08-19
yym8538/CVE-2026-40897
★ 1 · 2026-08-21
< Prev Page 56 / 446 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.