Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
360PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11114 results

CVE-2026-24088
FRESH PoC
PoCs 1 ★ 3 Last push 2026-10-09 (18 hours, 51 minutes ago)

Fetching description from NVD…

Show 1 repositories
aniketlab/POCO-M7-Plus-Jailbreak

Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)

★ 3 · 2026-10-09
CVE-2026-22732
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-09 (20 hours, 45 minutes ago)

Fetching description from NVD…

Show 3 repositories
semgrep/cve-2026-22732-demo

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

★ 0 · 2026-04-07
moderneinc/rewrite-cve-2026-22732
★ 0 · 2026-10-09
CVE-2026-88771
CRITICALFRESH PoCMULTI PoC
CVSS 9.5 CRITICAL CWE-20 Published 2026-09-27 PoCs 12 ★ 23 Last push 2026-10-09 (21 hours, 25 minutes ago)

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Show 8 of 12 repositories
ThomasPoppelgaard/netscaler-ctx697096-checker

Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…

★ 18 · 2026-10-08
technion/netscaler_scanner

Tooling related to CVE-2026-88771 and CVE-2026-88772

★ 1 · 2026-10-09
grupooruss/netscaler-defensive-checker

Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778

★ 1 · 2026-10-08
EXEcution-py/CVE-2026-88771-POC

Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total

★ 0 · 2026-09-28
techupdate24/citrix-netscaler-cve-2026-88771-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-28
SwiftSecur/CVE-2026-88771-HuntScript

A detection/hunting script for compromise related to CVE-2026-88771

★ 0 · 2026-09-29
CVE-2026-41089
FRESH PoCHOTMULTI PoC
PoCs 12 ★ 231 Last push 2026-10-09 (23 hours, 13 minutes ago)

Fetching description from NVD…

Show 8 of 12 repositories
0xABCD01/CVE-2026-41089

Netlogon and CLDAP vulnerability research with a proof of concept.

★ 231 · 2026-06-02
SyntaxMethod/CVE-2026-41089-Netlogon-RCE-PoC

CVE-2026-41089 Netlogon RCE PoC — security research, vulnerability validation & defensive testing.

★ 67 · 2026-09-11
HydraSoft/CVE-2026-41089-Netlogon-RCE

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon …

★ 34 · 2026-08-24
ADScanPro/CVE-2026-41089-LongLogon

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller…

★ 14 · 2026-06-04
hnytgl/CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

★ 13 · 2026-09-26
0xBlackash/CVE-2026-41089

CVE-2026-41089

★ 11 · 2026-06-05
ZeroDayVPN/CVE-2026-41089-Netlogon

🛡️ Official AI Security Tool diagnostic module for CVE-2026-41089 (Windows Netlogon Stack Buffer Overflow RCE). Features technical writeup, attack architecture…

★ 5 · 2026-09-29
opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

★ 1 · 2026-10-08
CVE-2026-57827
FRESH PoC
PoCs 4 ★ 16 Last push 2026-10-09 (23 hours, 18 minutes ago)

Fetching description from NVD…

Show 4 repositories
shinthink/CVE-2026-57827

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

★ 16 · 2026-07-29
Mohammad-008/rsfiles-CVE-2026-57827

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

★ 9 · 2026-08-03
jjkk123123/CVE-2026-57827

Joomla RSFiles 未授权文件上传CVE-2026-57827检测&利用脚本

★ 1 · 2026-08-06
Candisexterior171/CVE-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

★ 0 · 2026-10-09
CVE-2026-45585
FRESH PoCMULTI PoC
PoCs 11 ★ 7 Last push 2026-10-09 (23 hours, 18 minutes ago)

Fetching description from NVD…

Show 8 of 11 repositories
Desireeontrial76/yellowkey-bitlocker

Manage and recover BitLocker encrypted drives with this tool for Windows 11 recovery key management and educational study of CVE-2026-45585.

★ 7 · 2026-10-09
andrei-majer/bitlocker-hardening

BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

★ 5 · 2026-05-24
YellowKeyBitLocker-CVE/YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own.…

★ 3 · 2026-09-27
everest90909/YellowKey-WinRE-Remediation

Intune Remediation package for the CVE-2026-45585 YellowKey BitLocker/WinRE bypass mitigation described in the provided procedure. This package removes `autof…

★ 1 · 2026-05-21
0xBlackash/CVE-2026-45585

CVE-2026-45585

★ 1 · 2026-05-31
bjbakker1984/Yellowkey-mitigation

A small script to apply Yellowkey mitigation based on CVE-2026-45585 instructions

★ 0 · 2026-05-20
ChanderManiPandey2022/Yellow-Key-Check

YellowKey | BitLocker Bypass Vulnerability (CVE-2026-45585)

★ 0 · 2026-06-04
ChanderManiPandey2022/YellowKey-BitLocker-Bypass-CVE-2026-45585-Detect-Fix-Automatically-via-Microsoft-Intune

YellowKey | BitLocker Bypass CVE-2026-45585 | Detect & Fix Automatically via Microsoft Intune

★ 0 · 2026-06-08
CVE-2026-10520
FRESH PoCMULTI PoC
PoCs 8 ★ 13 Last push 2026-10-09 (23 hours, 22 minutes ago)

Fetching description from NVD…

Show 8 repositories
0xBlackash/CVE-2026-10520

CVE-2026-10520

★ 4 · 2026-06-11
HORKimhab/CVE-2026-10520-10523

CVE-2026-10520 and CVE-2026-10523

★ 0 · 2026-06-11
error-inside/CVE-2026-10520

Root-Level RCE via OS Command Injection in Ivanti Sentry

★ 0 · 2026-06-18
gduma-phData/patch-CVE-2026-10520

Patch: OGNL injection (Apache Struts)

★ 0 · 2026-08-24
01xJB/CVE-2026-10520-POC

Exploit for CVE-2026-10520 | Ivanti Sentry - OS Command Injection

★ 0 · 2026-10-09
CVE-2026-23744
FRESH PoCMULTI PoC
PoCs 40 ★ 12 Last push 2026-10-09 (23 hours, 23 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
boroeurnprach/CVE-2026-23744-PoC

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, …

★ 12 · 2026-06-14
suljov/CVE-2026-23744-Remote-Code-Execution-POC

MCPJam inspector contains a remote code execution

★ 12 · 2026-03-22
CerberusMrXi/CVE-2026-23744-MCPJam-Exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in version…

★ 6 · 2026-07-14
FrenzisRed/CVE-2026-23744

CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC

★ 4 · 2026-03-23
luiskrnr/exploit-CVE-2026-23744

MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request th…

★ 4 · 2026-04-10
Mluex0/CVE-2026-23744-PoC

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload …

★ 3 · 2026-08-11
InzegoSec/CVE-2026-23744

Exploit to MCPJam Inspector <=1.4.2

★ 1 · 2026-03-25
ctzisme/CVE-2026-23744

PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).

★ 1 · 2026-03-26
CVE-2026-31431
FRESH PoCHOTMULTI PoC
PoCs 325 ★ 4074 Last push 2026-10-09 (23 hours, 24 minutes ago)

Fetching description from NVD…

Show 8 of 325 repositories
theori-io/copy-fail-CVE-2026-31431

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

★ 4074 · 2026-04-29
tgies/copy-fail-c

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

★ 445 · 2026-07-17
badsectorlabs/copyfail-go

A Go implementation of copyfail (CVE-2026-31431)

★ 360 · 2026-05-01
Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated o…

★ 191 · 2026-05-07
Sndav/CVE-2026-31431-Advanced-Exploit

CVE-2026-31431 纯文件利用

★ 111 · 2026-04-30
painoob/Copy-Fail-Exploit-CVE-2026-31431

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or …

★ 109 · 2026-04-29
sgkdev/page_inject

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

★ 76 · 2026-05-06
Crihexe/copy-fail-tiny-elf-CVE-2026-31431

Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)

★ 63 · 2026-05-03
CVE-2026-31802
FRESH PoC
PoCs 3 ★ 1 Last push 2026-10-09 (23 hours, 30 minutes ago)

Fetching description from NVD…

Show 3 repositories
Jvr2022/CVE-2026-31802

PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.

★ 1 · 2026-03-14
Recorded-texteditor120/CVE-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

★ 1 · 2026-10-09
ridhinva/npm-tar-path-traversal-scanner

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

★ 0 · 2026-08-07
CVE-2025-14847
FRESH PoCMULTI PoC
PoCs 40 ★ 35 Last push 2026-10-09 (23 hours, 43 minutes ago)

Fetching description from NVD…

Show 8 of 40 repositories
Black1hp/mongobleed-scanner

MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool

★ 35 · 2025-12-28
cybertechajju/CVE-2025-14847_Expolit

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data from vulnera…

★ 34 · 2025-12-27
ProbiusOfficial/CVE-2025-14847

poc for CVE-2025-14847

★ 26 · 2025-12-26
onewinner/CVE-2025-14847

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

★ 15 · 2025-12-26
Security-Phoenix-demo/mongobleed-exploit-CVE-2025-14847

Exploit lab, docker and code scanner for mongobleed Vulnerability CVE-2025-14847 plus Phoenix Security Sync tools

★ 13 · 2026-01-03
codeb0ssx/CVE-2025-14847-PoC

Academic proof-of-concept demonstrating CVE-2025-14847 for authorized security research.

★ 4 · 2025-12-29
joshuavanderpoll/CVE-2025-14847

CVE-2025-14847 (MongoBleed)

★ 4 · 2025-12-29
franksec42/mongobleed-exploit-CVE-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

★ 3 · 2026-02-20
CVE-2024-0670
FRESH PoCMULTI PoC
PoCs 7 ★ 4 Last push 2026-10-09 (23 hours, 44 minutes ago)

Fetching description from NVD…

Show 7 repositories
elsevar11/CVE-2024-0670-CheckMK-Agent-Local-Privilege-Escalation-Exploit

This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for Windows. The vu…

★ 4 · 2025-11-16
magicrc/CVE-2024-0670

PoC for CVE-2024-0670

★ 2 · 2025-11-16
tralsesec/CVE-2024-0670

CheckMK Agent Local Privilege Escalation (PoC)

★ 1 · 2026-01-13
zhulin837/checkmk_cve-2024-0670
★ 0 · 2025-11-15
Nikopmpm/Fsociety-CVE-2024-0670-CheckMK-LPE

🔍 Exploit CVE-2024-0670 in CheckMK agents for local privilege escalation using a robust C++ tool designed for security professionals.

★ 0 · 2026-10-09
Nikopmpm/nikopmpm.github.io

🚀 Utilize this C++ tool for local privilege escalation on CheckMK agents, addressing the CVE-2024-0670 vulnerability effectively.

★ 0 · 2026-01-09
CVE-2025-55182
FRESH PoCHOTMULTI PoC
PoCs 462 ★ 2453 Last push 2026-10-09 (23 hours, 45 minutes ago)

Fetching description from NVD…

Show 8 of 462 repositories
assetnote/react2shell-scanner

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

★ 2453 · 2025-12-07
msanft/CVE-2025-55182

Explanation and full RCE PoC for CVE-2025-55182

★ 1431 · 2025-12-08
lachlan2k/React2Shell-CVE-2025-55182-original-poc

Original Proof-of-Concepts for React2Shell CVE-2025-55182

★ 1063 · 2025-12-05
ejpir/CVE-2025-55182-research

CVE-2025-55182 POC

★ 791 · 2025-12-08
mrknow001/RSC_Detector

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

★ 588 · 2025-12-05
emredavut/CVE-2025-55182

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478

★ 313 · 2025-12-06
ynsmroztas/NextRce

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

★ 266 · 2025-12-12
CVE-2025-26466
FRESH PoCMULTI PoC
PoCs 5 ★ 5 Last push 2026-10-09 (23 hours, 50 minutes ago)

Fetching description from NVD…

Show 5 repositories
rxerium/CVE-2025-26466

The OpenSSH client and server are vulnerable to a pre-authentication DoS attack between versions 9.5p1 to 9.9p1 (inclusive) that causes memory and CPU consump…

★ 5 · 2025-10-14
mrowkoob/CVE-2025-26466-msf

CVE-2025-26466 - SSH Ping DoS Ruby module for Metasploit Framework

★ 1 · 2025-06-23
tpirate/CVE-2025-26466

poc for CVE-2025-26466

★ 0 · 2026-04-02
acidboonrs/cve-2025-26466-openssh-poc

CVE-2025-26466 OpenSSH SSH2_MSG_PING DoS PoC

★ 0 · 2026-07-29
K0n9-log/cve-2025-26466-canvas
★ 0 · 2026-10-09
CVE-2021-26828
FRESH PoC
PoCs 3 ★ 9 Last push 2026-10-09 (23 hours, 58 minutes ago)

Fetching description from NVD…

Show 3 repositories
hev0x/CVE-2021-26828_ScadaBR_RCE
★ 9 · 2021-06-11
ridpath/CVE-2021-26828-Ultimate

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

★ 5 · 2025-12-02
h002733/CVE-2021-26828

Corrected python code for CVE-2021-26828

★ 0 · 2026-10-09
CVE-2026-80428
FRESH PoC
PoCs 3 ★ 2 Last push 2026-10-09 (1 day ago)

Fetching description from NVD…

Show 3 repositories
HackfutSecRoot/CVE-2026-80428

ILIAS ≤ 9.21 / 10.9 / 11.2 — Unauthenticated PHP Object Injection (RCE)

★ 2 · 2026-10-09
digiprosec/CVE-2026-80428

CVE-2026-80428 PoC

★ 0 · 2026-09-03
CVE-2026-81000
FRESH PoC
PoCs 3 ★ 0 Last push 2026-10-09 (1 day, 1 hour ago)

Fetching description from NVD…

Show 3 repositories
suominen/tunderflow

Tracking TUNderflow (CVE-2026-81000), the Linux kernel TUN/TAP receive-headroom underflow

★ 0 · 2026-10-09
0xBlackash/CVE-2026-81000

CVE-2026-81000

★ 0 · 2026-09-28
HORKimhab/CVE-2026-81000

CVE-2026-81000

★ 0 · 2026-09-21
CVE-2021-30535
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-415 Published 2021-06-07 PoCs 1 ★ 0 Last push 2026-10-09 (1 day, 1 hour ago) Discovered 2026-10-09 03:16

Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Show 1 repositories
califio/icu4x-crubit-demo

C++ contact-list demo comparing vulnerable ICU4C 66.1 with ICU4X through Crubit (CVE-2021-30535).

★ 0 · 2026-10-09
CVE-2025-34069
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-09 (1 day, 2 hours ago)

Fetching description from NVD…

Show 1 repositories
cppghoul/CVE-2025-34069

Kerio Control 9.4.5 Auth Bypass PoC

★ 1 · 2026-10-09
CVE-2026-53921
FRESH PoC
PoCs 2 ★ 6 Last push 2026-10-09 (1 day, 2 hours ago)

Fetching description from NVD…

Show 2 repositories
tc4dy/CVE-2026-53921-PoC-Exploit

CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (I…

★ 6 · 2026-10-09
0xBlackash/CVE-2026-53921

CVE-2026-53921

★ 2 · 2026-07-28
CVE-2026-23479
FRESH PoC
PoCs 4 ★ 1 Last push 2026-10-09 (1 day, 3 hours ago)

Fetching description from NVD…

Show 4 repositories
HackSpeak/CVE-2026-23479

Redis CVE-2026-23479 UAF RCE vulnerability checker mirror — pduggusa, MIT; for authorized security testing

★ 1 · 2026-08-19
pduggusa/redis-cve-2026-23479-check

Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By Dugga…

★ 0 · 2026-06-04
v1c0mmrt/redis-cve-2026-23479-scanner

CVE-2026-23479 Redis Use-After-Free vulnerability detection tool

★ 0 · 2026-06-13
rizlmaulanaa/CVE-2026-23479-Redis-UAF-Proof-of-Concept

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

★ 0 · 2026-10-09
CVE-2019-11707
FRESH PoC
PoCs 4 ★ 42 Last push 2026-10-09 (1 day, 4 hours ago)

Fetching description from NVD…

Show 4 repositories
vigneshsrao/CVE-2019-11707

Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu

★ 42 · 2019-08-18
flabbergastedbd/cve-2019-11707

https://bugs.chromium.org/p/project-zero/issues/detail?id=1820

★ 2 · 2020-04-14
CosminGGeorgescu/CVE-2019-11707-PoC

Proof of concept for CVE-2019-11707

★ 0 · 2026-02-05
G4sp4rCS/CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-

CVE-2019-11707 is a critical type confusion in Firefox's IonMonkey optimizing JIT. The browser bug provides native code execution in the content process, but t…

★ 0 · 2026-10-09
CVE-2021-1931
FRESH PoCHOT
PoCs 4 ★ 212 Last push 2026-10-09 (1 day, 4 hours ago)

Fetching description from NVD…

Show 4 repositories
starseed12345/QuestStack

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

★ 212 · 2026-08-28
FakeShell/CVE-2021-1931-BBRY-KEY2

proof of concept CVE-2021-1931 exploit for the blackberry key2 (le) that allows to flash unsigned images temporarily

★ 8 · 2025-05-04
aomsin2526/xperia_5_bl_unlocker_poc

My take on unlocking Xperia 5 SO-01M for p42 bootloader using CVE-2021-1931

★ 5 · 2026-10-09
stanw47/Blackberry-Key2-Research

BlackBerry KEY2 (BBF100-6) bootloader unlock (CVE-2021-1931), unlock-tool RE, recon, and LineageOS research

★ 1 · 2026-10-05
CVE-2026-59310
FRESH PoCMULTI PoC
PoCs 5 ★ 4 Last push 2026-10-09 (1 day, 5 hours ago)

Fetching description from NVD…

Show 5 repositories
ChinaRan0/CVE-2026-59310-POC

CVE-2026-59310-POC 仅用于自测,请勿用于攻击

★ 4 · 2026-09-25
BiuTrap/CVE-2026-59310

CVE-2026-59310 PoC

★ 2 · 2026-08-19
chu0119/vc-strike

VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only…

★ 1 · 2026-10-03
HORKimhab/CVE-2026-59310

CVE-2026-59310

★ 0 · 2026-08-17
vpxuser/CVE-2026-59310

ChinaRan0/CVE-2026-59310-POC 的优化版本。子命令、一次性 cron、带远端 PTY 的交互 shell。仅限授权测试。

★ 0 · 2026-10-09
CVE-2026-55450
CRITICALFRESH PoC
CVSS 9.3 CRITICAL CWE-200, CWE-306, CWE-400 Published 2026-06-23 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 7 hours ago) Discovered 2026-10-09 03:16

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.

Show 1 repositories
0xBlackash/CVE-2026-55450

CVE-2026-55450

★ 0 · 2026-10-08
< Prev Page 6 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.