Fetching description from NVD…
Show 1 repositories
Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11114 results
Fetching description from NVD…
Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)
Fetching description from NVD…
Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…
Tooling related to CVE-2026-88771 and CVE-2026-88772
Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778
Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
A detection/hunting script for compromise related to CVE-2026-88771
Fetching description from NVD…
Netlogon and CLDAP vulnerability research with a proof of concept.
CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.
Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …
CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
CVE-2026-41089
🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…
Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.
Fetching description from NVD…
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.
Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
Fetching description from NVD…
Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.
BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)
YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own.…
Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…
CVE-2026-45585
A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions
YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)
YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune
Fetching description from NVD…
CVE-2026-10520
CVE-2026-10520 and CVE-2026-10523
Root-Level RCE via OS Command Injection in Ivanti Sentry
Patch: OGNL injection (Apache Struts)
Exploit for CVE-2026-10520 | Ivanti Sentry - OS Command Injection
Fetching description from NVD…
CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …
MCPJam inspector contains a remote code execution
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in version…
CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …
Exploit to MCPJam Inspector <=1.4.2
PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).
Fetching description from NVD…
Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.
A Go implementation of copyfail (CVE-2026-31431)
PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…
CVE-2026-31431 纯文件利用
Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …
CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)
Fetching description from NVD…
PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.
Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.
Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack
Fetching description from NVD…
MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool
a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…
poc for CVE-2025-14847
MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具
Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools
Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.
CVE-2025-14847 (MongoBleed)
Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader
Fetching description from NVD…
This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for Windows. The vu…
PoC for CVE-2024-0670
CheckMK Agent Local Privilege Escalation (PoC)
🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.
🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.
Fetching description from NVD…
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
Explanation and full RCE PoC for CVE-2025-55182
Original Proof-of-Concepts for React2Shell CVE-2025-55182
CVE-2025-55182 POC
Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.
RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478
React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)
Fetching description from NVD…
The OpenSSH client and server are vulnerable to a pre-authentication DoS attack between versions 9.5p1 to 9.9p1 (inclusive) that causes memory and CPU consump…
CVE-2025-26466 - SSH Ping DoS Ruby module for Metasploit Framework
poc for CVE-2025-26466
CVE-2025-26466 OpenSSH SSH2_MSG_PING DoS PoC
Fetching description from NVD…
ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
Corrected python code for CVE-2021-26828
Fetching description from NVD…
ILIAS ≤ 9.21 / 10.9 / 11.2 — Unauthenticated PHP Object Injection (RCE)
CVE-2026-80428 PoC
Fetching description from NVD…
Tracking TUNderflow (CVE-2026-81000), the Linux kernel TUN/TAP receive-headroom underflow
CVE-2026-81000
CVE-2026-81000
Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
C++ contact-list demo comparing vulnerable ICU4C 66.1 with ICU4X through Crubit (CVE-2021-30535).
Fetching description from NVD…
Kerio Control 9.4.5 Auth Bypass PoC
Fetching description from NVD…
CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (I…
CVE-2026-53921
Fetching description from NVD…
Redis CVE-2026-23479 UAF RCE vulnerability checker mirror — pduggusa, MIT; for authorized security testing
Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By Dugga…
CVE-2026-23479 Redis Use-After-Free vulnerability detection tool
Proof of concept with GDB‑assisted exploitation (educational / lab use only)
Fetching description from NVD…
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu
https://bugs.chromium.org/p/project-zero/issues/detail?id=1820
Proof of concept for CVE-2019-11707
CVE-2019-11707 is a critical type confusion in Firefox's IonMonkey optimizing JIT. The browser bug provides native code execution in the content process, but t…
Fetching description from NVD…
Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.
proof of concept CVE-2021-1931 exploit for the blackberry key2 (le) that allows to flash unsigned images temporarily
My take on unlocking Xperia 5 SO-01M for p42 bootloader using CVE-2021-1931
BlackBerry KEY2 (BBF100-6) bootloader unlock (CVE-2021-1931), unlock-tool RE, recon, and LineageOS research
Fetching description from NVD…
CVE-2026-59310-POC 仅用于自测,请勿用于攻击
CVE-2026-59310 PoC
VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only…
CVE-2026-59310
ChinaRan0/CVE-2026-59310-POC 的优化版本。子命令、一次性 cron、带远端 PTY 的交互 shell。仅限授权测试。
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.
CVE-2026-55450
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.