Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11114CVEs tracked
26004PoC repositories
17New in 24h
357PoC updated in 7 days
filters
All New Fresh PoC Hot Multi PoC Critical High

11114 results

CVE-2026-102253
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 15 hours ago)

Fetching description from NVD…

Show 1 repositories
Ravi-lk/CVE-2026-102253-POC

DOS infinite-loop Vulnerability POC

★ 0 · 2026-10-07
CVE-2026-90977
FRESH PoC
CVSS 5.3 MEDIUM CWE-697 Published 2026-09-18 PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.

Show 1 repositories
aminquliyev057/CVE-2026-90977

Clean Login < 1.19 - Unauthenticated CAPTCHA Bypass via Empty Session Comparison

★ 0 · 2026-10-07
CVE-2026-76555
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
Hasyros/CVE-2026-76555-path-traversal-wp-import-export-lite

WP Import Export Lite < 3.9.33 - Authenticated Path Traversal to Sensitive File Disclosure

★ 0 · 2026-10-07
CVE-2026-101162
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-101161
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2026-101160
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
CVE-2021-38759
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 16 hours ago)

Fetching description from NVD…

Show 1 repositories
Hu2ie/CVE-2021-38759

CVE-2021-38759 — Raspberry Pi OS Default Credentials Exploit

★ 0 · 2026-10-07
CVE-2026-96451
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-639 Published 2026-10-03 PoCs 2 ★ 1 Last push 2026-10-07 (2 days, 16 hours ago)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

Show 2 repositories
MRdark-ops/wpexploit-CVE-2026-96451

Privilege Escalation vulnerability

★ 1 · 2026-10-07
Nxploited/CVE-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

★ 0 · 2026-10-04
CVE-2026-93661
FRESH PoC
CVSS 2.7 LOW CWE-639 Published 2026-09-24 PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 17 hours ago)

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.

Show 1 repositories
Hasyros/CVE-2026-93661-idor-events-manager

IDOR/BOLA in Events Manager <= 7.4.3 REST ticket update endpoint — CVE-2026-93661

★ 0 · 2026-10-07
CVE-2026-13043
FRESH PoC
PoCs 1 ★ 1 Last push 2026-10-07 (2 days, 17 hours ago)

Fetching description from NVD…

Show 1 repositories
TheMalwareGuardian/CVE-2026-13043

CVE-2026-13043 - Exploiting Panda / WatchGuard pskmad.sys authentication bypass for privileged IOCTL access, MSR disclosure and arbitrary process memory reads.

★ 1 · 2026-10-07
CVE-2024-4367
FRESH PoCHOTMULTI PoC
PoCs 27 ★ 203 Last push 2026-10-07 (2 days, 18 hours ago)

Fetching description from NVD…

Show 8 of 27 repositories
LOURC0D3/CVE-2024-4367-PoC

CVE-2024-4367 & CVE-2024-34342 Proof of Concept

★ 203 · 2024-06-07
s4vvysec/CVE-2024-4367-POC

CVE-2024-4367 arbitrary js execution in pdf js

★ 57 · 2024-05-20
Zombie-Kaiser/cve-2024-4367-PoC-fixed

PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 (<126),因为 Firefox 使用 PDF.js 来显示 PDF 文件,但也严重影响了许多基于 Web 和 Elec…

★ 12 · 2024-06-13
spaceraccoon/detect-cve-2024-4367

YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js

★ 11 · 2024-05-27
snyk-labs/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 10 · 2026-10-07
UnHackerEnCapital/PDFernetRemotelo

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

★ 6 · 2024-06-20
Masamuneee/CVE-2024-4367-Analysis

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

★ 5 · 2024-09-04
clarkio/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367

★ 4 · 2024-11-10
CVE-2024-7971
FRESH PoC
PoCs 2 ★ 36 Last push 2026-10-07 (2 days, 20 hours ago)

Fetching description from NVD…

Show 2 repositories
mistymntncop/CVE-2024-7971
★ 36 · 2025-04-14
pepoc3/cve-2024-7971-poc

CVE-2024-7971 OPPO Browser (Chromium 115) remote DoS PoC - OSRC verification only

★ 0 · 2026-10-07
CVE-2026-81780
FRESH PoC
PoCs 2 ★ 0 Last push 2026-10-07 (2 days, 21 hours ago)

Fetching description from NVD…

Show 2 repositories
0xTerror/CVE-2026-81780-Hash-Form

CVE-2026-81780 — Hash Form RCE

★ 0 · 2026-09-07
0xCyp1337/CVE-2026-81780
★ 0 · 2026-10-07
CVE-2019-2215
FRESH PoCHOTMULTI PoC
PoCs 33 ★ 137 Last push 2026-10-07 (2 days, 21 hours ago)

Fetching description from NVD…

Show 8 of 33 repositories
kangtastic/cve-2019-2215

Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215

★ 137 · 2019-10-15
timwr/CVE-2019-2215
★ 79 · 2019-11-12
sharif-dev/AndroidKernelVulnerability

Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215

★ 73 · 2022-09-04
0xbinder/android-kernel-exploitation-lab

This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.

★ 44 · 2025-04-24
DimitriFourny/cve-2019-2215

Android privilege escalation via an use-after-free in binder.c

★ 41 · 2020-04-14
LIznzn/CVE-2019-2215

Temproot for Bravia TV via CVE-2019-2215.

★ 26 · 2020-02-20
stevejubx/CVE-2019-2215

Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC

★ 17 · 2023-12-21
c3r34lk1ll3r/CVE-2019-2215

PoC for old Binder vulnerability (based on P0 exploit)

★ 14 · 2020-10-27
CVE-2019-8900
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 22 hours ago)

Fetching description from NVD…

Show 1 repositories
Weeabo-Inc/a9pwn

checkm8 (CVE-2019-8900) for Apple A9, native to Linux — and a verdict system that never confuses 'this host cannot reset' with 'the exploit did not work'.

★ 0 · 2026-10-07
CVE-2025-26125
FRESH PoCHOT
PoCs 1 ★ 171 Last push 2026-10-07 (2 days, 22 hours ago)

Fetching description from NVD…

Show 1 repositories
ZeroMemoryEx/CVE-2025-26125

( 0day ) Local Privilege Escalation in IObit Malware Fighter

★ 171 · 2026-10-07
CVE-2026-102489
FRESH PoC
PoCs 2 ★ 6 Last push 2026-10-07 (2 days, 23 hours ago)

Fetching description from NVD…

Show 2 repositories
horizon3ai/CVE-2026-102489

Zammad Session Leak to Remote Code Execution

★ 6 · 2026-10-07
CVE-2024-23652
FRESH PoC
PoCs 2 ★ 2 Last push 2026-10-07 (2 days, 23 hours ago)

Fetching description from NVD…

Show 2 repositories
abian2/CVE-2024-23652
★ 2 · 2024-03-01
hgyc/CVE-stand

Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs

★ 0 · 2026-10-07
CVE-2022-0492
FRESH PoCMULTI PoC
PoCs 8 ★ 47 Last push 2026-10-07 (2 days, 23 hours ago)

Fetching description from NVD…

Show 8 repositories
PaloAltoNetworks/can-ctr-escape-cve-2022-0492

Test whether a container environment is vulnerable to container escapes via CVE-2022-0492

★ 47 · 2022-03-09
chenaotian/CVE-2022-0492

CVE-2022-0492 EXP and Analysis write up

★ 35 · 2022-03-11
SofianeHamlaoui/CVE-2022-0492-Checker

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

★ 13 · 2022-03-12
T1erno/CVE-2022-0492-Docker-Breakout-Checker-and-PoC

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

★ 8 · 2023-02-18
KianaBin/CVE-2022-0492-Container-Escape

CVE-2022-0492-Container-Escape

★ 2 · 2022-08-28
Perimora/cve_2022_0492

PoC for CVE-2022-0492

★ 0 · 2025-07-20
hgyc/CVE-stand

Reproduction and verification of container-escape CVEs (CVE-2022-0492, CVE-2024-23652) in isolated Docker labs

★ 0 · 2026-10-07
CVE-2026-39987
FRESH PoCMULTI PoC
PoCs 27 ★ 9 Last push 2026-10-07 (3 days, 1 hour ago)

Fetching description from NVD…

Show 8 of 27 repositories
Th3Purge/CVE-2026-39987

Marimo Pre Authentication RCE

★ 9 · 2026-09-08
M3PH1569/CVE-2026-39987-POC

CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)

★ 5 · 2026-07-19
keraattin/CVE-2026-39987

CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE (CVSS 9.3). Python & Nmap NSE detection scripts. Missing authentication on /terminal/ws WebSocket endpoint …

★ 1 · 2026-04-15
Nxploited/CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

★ 1 · 2026-04-18
h3raklez/CVE-2026-39987

Marimo Pre-Auth RCE

★ 1 · 2026-04-25
Wind010/CVE-2026-39987_PoC

A proof-of-concept for CVE-2026-39987

★ 1 · 2026-08-03
Ghxstsec/CVE-2026-39987
★ 1 · 2026-09-01
CVE-2026-93355
HIGHFRESH PoC
CVSS 7.6 HIGH CWE-1390 Published 2026-09-28 PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 1 hour ago)

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.

Show 1 repositories
InertFluid/cve-2026-93355-lab

Benign, offline reproduction of CVE-2026-93355 — LiteLLM unverified-email JWT account takeover (runs LiteLLM's real code)

★ 0 · 2026-10-07
CVE-2026-87902
HIGHFRESH PoCMULTI PoC
CVSS 8.1 HIGH CWE-98 Published 2026-09-22 PoCs 26 ★ 38 Last push 2026-10-07 (3 days, 1 hour ago)

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Show 8 of 26 repositories
ressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable l…

★ 38 · 2026-09-22
abraxas/CVE-2026-87902

CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)

★ 35 · 2026-10-07
dinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional RCE (WP 4…

★ 13 · 2026-09-23
tc4dy/CVE-2026-87902-Toolkit

CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create,…

★ 11 · 2026-09-27
vulpecuna/CVE-2026-87902

Unauthenticated RCE on Wordpress

★ 9 · 2026-09-23
tonydelouvre/CVE-2026-87902

XWP_RCE — CVE-2026-87902 Hacker Console

★ 4 · 2026-09-29
ynsmroztas/WPSniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

★ 3 · 2026-09-23
crowsec-edtech/CVE-2026-87902

Proof of concept for vulnerability CVE-2026-87902 in Wordpress

★ 3 · 2026-09-25
CVE-2026-85102
FRESH PoC
PoCs 1 ★ 0 Last push 2026-10-07 (3 days, 1 hour ago)

Fetching description from NVD…

Show 1 repositories
aduli198/CVE-2026-85102

Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN

★ 0 · 2026-10-07
CVE-2020-1472
FRESH PoCHOTMULTI PoC
PoCs 75 ★ 1837 Last push 2026-10-07 (3 days, 1 hour ago)

Fetching description from NVD…

Show 8 of 75 repositories
bvcyber/CVE-2020-1472

Test tool for CVE-2020-1472

★ 1837 · 2025-06-27
dirkjanm/CVE-2020-1472

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

★ 1329 · 2020-11-03
risksense/zerologon

Exploit for zerologon cve-2020-1472

★ 708 · 2020-10-15
VoidSec/CVE-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

★ 399 · 2020-11-05
bb00/zer0dump

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

★ 179 · 2023-03-02
mstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

★ 113 · 2020-09-16
Rvn0xsy/ZeroLogon

CVE-2020-1472 C++

★ 83 · 2022-09-02
zeronetworks/zerologon

Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB

★ 61 · 2023-05-01
CVE-2016-5195
FRESH PoCHOTMULTI PoC
PoCs 62 ★ 1015 Last push 2026-10-07 (3 days, 3 hours ago)

Fetching description from NVD…

Show 8 of 62 repositories
timwr/CVE-2016-5195

CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android

★ 1015 · 2021-02-03
firefart/dirtycow

Dirty Cow exploit - CVE-2016-5195

★ 932 · 2025-07-30
scumjr/dirtycow-vdso

PoC for Dirty COW (CVE-2016-5195)

★ 512 · 2022-03-16
gbonacini/CVE-2016-5195

A CVE-2016-5195 exploit example.

★ 341 · 2017-03-21
r1is/CVE-2022-0847

CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-…

★ 282 · 2023-02-02
hyln9/VIKIROOT

CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow

★ 271 · 2017-01-27
Brucetg/DirtyCow-EXP

编译好的脏牛漏洞(CVE-2016-5195)EXP

★ 141 · 2018-05-27
DavidBuchanan314/cowroot

Universal Android root tool based on CVE-2016-5195. Watch this space.

★ 32 · 2016-10-29
< Prev Page 9 / 445 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.