Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live
CVE-2026-88776
CVE-2026-84520
CVE-2026-51994
CVE-2026-107181
CVE-2026-104587
CVE-2026-104586
CVE-2026-104585
CVE-2026-104584
CVE-2025-34071
CVE-2026-95149
CVE-2026-94597
CVE-2026-28775
CVE-2026-24046
CVE-2026-107406
14 contacts in last 24h
11114CVEs tracked
26004PoC repositories
17New in 24h
360PoC updated in 7 days
filters
11114 results
PoCs 4
★ 1
Last push 2026-10-08 (1 day, 9 hours ago)
Fetching description from NVD…
Show 4 repositories
abraxas/CVE-2026-5430
CVE-2026-5430 - WSO2 API Manager - Critical 10.0 - Unauthenticated Account Takeover - WSO2 API Control Plane, WSO2 API Manager, WSO2 Traffic Manager, WSO2 Univ…
★ 1 · 2026-10-07
davidvrns/CVE-2026-5430-WSO2
Detection PoC for CVE-2026-5430 — unauthenticated JWT algorithm bypass (CVSS 10.0) affecting WSO2 API Manager 4.1.0–4.6.0. Read-only assessment tool with patch…
★ 0 · 2026-10-08
getdrive/wso2_cve-2026-5430_lab
Уязвимая лаборатория WSO2 API Manager 4.5.0 в Docker, сканер и эксплойт для CVE-2026-5430 (обход аутентификации через поддельный HS256 JWT)
★ 0 · 2026-10-08
PoCs 3
★ 453
Last push 2026-10-08 (1 day, 10 hours ago)
Fetching description from NVD…
Show 3 repositories
LSPosed/LSPromise
Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
★ 453 · 2026-09-09
Supersonic/TLPE
CVE-2026-49881, using insecure context creation in Android 17's Telecom service to execute arbitrary code as UID 1000 system_server from an unprivileged app
★ 104 · 2026-09-09
PoCs 3
★ 4
Last push 2026-10-08 (1 day, 10 hours ago)
Fetching description from NVD…
Show 3 repositories
HackSpeak/CVE-2026-67279
MikroTrick (MikroTik RouterOS SSH takeover chain) PoC mirror - CVE-2026-67279 + CVE-2026-86060 (+67276); for authorized lab testing
★ 4 · 2026-09-26
tc4dy/CVE-2026-67279-86060-Toolkit
CVE-2026-67279 + CVE-2026-86060 – MikroTrick MikroTik RouterOS SSH Pre-Auth Takeover (CVSS 9.2) | Red/Blue Team suite. 2 tools: Full Exploit (rekey bypass, fd-…
★ 3 · 2026-09-27
PoCs 7
★ 2
Last push 2026-10-08 (1 day, 10 hours ago)
Fetching description from NVD…
Show 7 repositories
aish19siddiqua-commits/mtechweek_04
Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink…
★ 0 · 2026-08-22
ocfagb/hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-12…
★ 0 · 2026-08-27
PoCs 2
★ 2
Last push 2026-10-08 (1 day, 10 hours ago)
Fetching description from NVD…
Show 2 repositories
CVSS 8.7 HIGH
CWE-22
Published 2026-09-15
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 10 hours ago)
Discovered 2026-10-09 03:16
crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.
Show 1 repositories
PoCs 4
★ 35
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 4 repositories
tc4dy/CVE-2026-60206-PoC-Exploit
CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework | Bash & Python versions. Features: --detect safe check, --exploit combo/unsigned/xsw/namei…
★ 4 · 2026-10-08
Debajyoti0-0/CVE-2026-60206
Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.
★ 1 · 2026-07-25
PoCs 26
★ 56
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 8 of 26 repositories
wordsec/XSS2Shell
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
★ 7 · 2026-08-07
HackSpeak/CVE-2026-64638
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing
★ 2 · 2026-08-08
PoCs 2
★ 5
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 2 repositories
tc4dy/CVE-2026-58048-PoC-Exploit
CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe Checker (audit/…
★ 5 · 2026-10-08
PoCs 14
★ 43
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 8 of 14 repositories
guneykabel/cve-2026-85706
Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1
★ 43 · 2026-09-11
plur1bu5/gitread
CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting
★ 1 · 2026-09-13
CVSS 9.8 CRITICAL
CWE-201
Published 2026-10-08
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 11 hours ago)
Discovered 2026-10-09 03:16
Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources.
This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26.
Show 1 repositories
PoCs 2
★ 13
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 2 repositories
tc4dy/CVE-2026-65643-PoC-Toolkit
CVE-2026-65643 – cPanel Domain Parking RCE Toolkit (CVSS 8.7) | Red/Blue Team suite for unpatched cPanel & WHM 11.x (110,134,136,138). 2 tools: Full Exploit (r…
★ 13 · 2026-10-08
PoCs 8
★ 12
Last push 2026-10-08 (1 day, 11 hours ago)
Fetching description from NVD…
Show 8 repositories
tc4dy/CVE-2026-82329-PoC-Exploit
CVE-2026-82329 – JFrog Artifactory Auth Bypass Toolkit (CVSS 9.8) | Red/Blue Team suite for self-hosted Artifactory 7.x (111-161). 2 tools: Full Exploit (JWTfo…
★ 3 · 2026-10-08
0xCyp1337/CVE-2026-82329
CVE‑2026‑82329 is a critical authentication bypass in JFrog Artifactory (CVSS 9.8) allowing unauthenticated attackers to obtain full administrative privileges.…
★ 0 · 2026-09-03
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 12 hours ago)
Discovered 2026-10-09 03:16
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 15 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 0
Last push 2026-10-08 (1 day, 15 hours ago)
Fetching description from NVD…
Show 1 repositories
PoCs 1
★ 6
Last push 2026-10-08 (1 day, 16 hours ago)
Fetching description from NVD…
Show 1 repositories
grisuno/CVE-2022-22077
CVE-2022-22077 is a high-severity vulnerability (CVSS score 7.8) affecting the RTCore64.sys driver distributed with MSI Center
★ 6 · 2026-10-08
PoCs 45
★ 64
Last push 2026-10-08 (1 day, 16 hours ago)
Fetching description from NVD…
Show 8 of 45 repositories
iammerrida-source/nginx-rift-detect
Behavioral detection script for CVE-2026-42945 (NGINX Rift) — heap overflow in ngx_http_rewrite_module. No RCE, crash-based detection only.
★ 4 · 2026-05-15
PoCs 25
★ 30
Last push 2026-10-08 (1 day, 17 hours ago)
Fetching description from NVD…
Show 8 of 25 repositories
orange0Mint/CVE-2025-57819_FreePBX
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using…
★ 2 · 2025-09-18
PoCs 5
★ 20
Last push 2026-10-08 (1 day, 17 hours ago)
Fetching description from NVD…
Show 5 repositories
PoCs 3
★ 55
Last push 2026-10-08 (1 day, 17 hours ago)
Fetching description from NVD…
Show 3 repositories
PoCs 15
★ 278
Last push 2026-10-08 (1 day, 17 hours ago)
Fetching description from NVD…
Show 8 of 15 repositories
Qingizi7/cve-2025-21479_iqooneo8
Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell
★ 7 · 2026-09-06
RamenFast/zenfone9-root
Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.
★ 4 · 2026-09-18
PoCs 7
★ 21
Last push 2026-10-08 (1 day, 18 hours ago)
Fetching description from NVD…
Show 7 repositories
nullxall/cve-2025-62215-exploit-poc
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploited as a z…
★ 1 · 2025-11-14
PoCs 3
★ 0
Last push 2026-10-08 (1 day, 18 hours ago)
Fetching description from NVD…
Show 3 repositories
sarjanpatel22/siem-threat-detection-lab
Blue-team SIEM lab: Wazuh 4.7.5 detecting 7 simulated attacks (SSH brute force, Slowloris DoS / CVE-2007-6750, web attacks) with real-time MITRE ATT&CK mapping…
★ 0 · 2026-07-02
RoflSecurity/nodeloris
While the name of this tool sounds like a spell straight out of the Harry Potter universe, it is actually a DoS tool based on SlowLoris (CVE-2007-6750).
★ 0 · 2026-10-05
PoCs 12
★ 18
Last push 2026-10-08 (1 day, 19 hours ago)
Fetching description from NVD…
Show 8 of 12 repositories
papageo75/CVE-2026-48908-PoC
Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guard…
★ 18 · 2026-06-23
Jenderal92/CVE-2026-48908
CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell verification. Fo…
★ 3 · 2026-07-08
ayiezola/CVE-2026-48908
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
★ 0 · 2026-06-25
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.