Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

60 results

CVE-2026-28775
NEWCRITICALFRESH PoC
CVSS 10.0 CRITICAL CWE-1188 Published 2026-03-04 PoCs 1 ★ 0 Last push 2026-10-09 (16 hours, 11 minutes ago) Discovered 2026-10-09 14:08

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Show 1 repositories
Udyz/CVE-2026-28775

CVE-2026-28775 SNMP RCE

★ 0 · 2026-10-09
CVE-2026-88771
CRITICALFRESH PoCMULTI PoC
CVSS 9.5 CRITICAL CWE-20 Published 2026-09-27 PoCs 12 ★ 23 Last push 2026-10-09 (18 hours, 15 minutes ago)

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Show 8 of 12 repositories
ThomasPoppelgaard/netscaler-ctx697096-checker

Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…

★ 18 · 2026-10-08
technion/netscaler_scanner

Tooling related to CVE-2026-88771 and CVE-2026-88772

★ 1 · 2026-10-09
grupooruss/netscaler-defensive-checker

Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778

★ 1 · 2026-10-08
EXEcution-py/CVE-2026-88771-POC

Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total

★ 0 · 2026-09-28
techupdate24/citrix-netscaler-cve-2026-88771-rce

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-09-28
SwiftSecur/CVE-2026-88771-HuntScript

A detection/hunting script for compromise related to CVE-2026-88771

★ 0 · 2026-09-29
CVE-2026-107406
NEWCRITICALFRESH PoC
CVSS 9.5 CRITICAL CWE-119 Published 2026-10-08 PoCs 2 ★ 0 Last push 2026-10-09 (18 hours, 31 minutes ago) Discovered 2026-10-09 14:08

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Show 2 repositories
techupdate24/citrix-netscaler-rce-cve-2026-107406

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-09
ApexBreach/CVE-2026-107406-Poc
★ 0 · 2026-10-09
CVE-2016-10134
CRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-89 Published 2017-02-17 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 31 minutes ago) Discovered 2026-10-09 03:16

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

Show 1 repositories
CyberCTF/vulhub-zabbix-cve-2016-10134

Vulhub zabbix/CVE-2016-10134: Zabbix latest.php and jsrpc.php SQL Injection (CVE-2016-10134), run with Isoloom

★ 0 · 2026-10-09
CVE-2026-55450
CRITICALFRESH PoC
CVSS 9.3 CRITICAL CWE-200, CWE-306, CWE-400 Published 2026-06-23 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 4 hours ago) Discovered 2026-10-09 03:16

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.

Show 1 repositories
0xBlackash/CVE-2026-55450

CVE-2026-55450

★ 0 · 2026-10-08
CVE-2026-92555
CRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-201 Published 2026-10-08 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 7 hours ago) Discovered 2026-10-09 03:16

Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26.

Show 1 repositories
Enay-Project/CVE-2026-92555

CVE-2026-92555 Exploit

★ 0 · 2026-10-08
CVE-2026-87796
CRITICALFRESH PoC
CVSS 9.8 CRITICAL CWE-434 Published 2026-09-17 PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 2 hours ago)

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Show 1 repositories
abraxas/CVE-2026-87796

CVE-2026-87796 - Multi Uploader for Gravity Forms <= 1.1.9; Unauthorized RCE (CRITICAL 9.8)

★ 1 · 2026-10-07
CVE-2026-86350
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-444 Published 2026-09-23 PoCs 1 ★ 1 Last push 2026-10-07 (3 days, 2 hours ago)

Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Show 1 repositories
abraxas/CVE-2026-86350

CVE-2026-86350 - Apache Tomcat - Critical 9.1 - Unauthenticated GET /header.jsp - HTTP/2 Request Header Mix-up (Request Smuggling)

★ 1 · 2026-10-07
CVE-2026-92701
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-346, CWE-354 Published 2026-09-18 PoCs 1 ★ 3 Last push 2026-10-06 (3 days, 23 hours ago)

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.

Show 1 repositories
muhammad-usama-sardar/intra-handshake-fail

Early Attestation Considered Very Harmful (CVE-2026-92701, CVE-2026-92702, CVE-2026-33697, and more to come)

★ 3 · 2026-10-06
CVE-2026-86881
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-295 Published 2026-09-14 PoCs 1 ★ 0 Last push 2026-10-05 (5 days, 1 hour ago)

A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usages.

Show 1 repositories
0xcrypto/CVE-2026-86881

Analysis of CVE-2026-86881: An attacker with a compromised intermediate certificate authority may be able to issue certificates with arbitrary extended key usa…

★ 0 · 2026-10-05
CVE-2026-92084
CRITICALFRESH PoC
CVSS 9.1 CRITICAL CWE-94 Published 2026-10-03 PoCs 1 ★ 0 Last push 2026-10-04 (5 days, 17 hours ago)

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.

Show 1 repositories
Hassham1/CVE-2026-92084-beaver-builder-shortcode-poc

CVE-2026-92084 — Beaver Builder Lite <= 2.11.0.5 unauthenticated arbitrary shortcode execution via Sidebar module widget output (CVSS 9.1): Docker validation l…

★ 0 · 2026-10-04
CVE-2026-90970
CRITICALFRESH PoC
CVSS 9.9 CRITICAL CWE-1336 Published 2026-10-02 PoCs 1 ★ 0 Last push 2026-10-03 (6 days, 16 hours ago)

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

Show 1 repositories
techupdate24/gitlab-ai-gateway-cve-2026-90970

A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

★ 0 · 2026-10-03
CVE-2026-9558
CRITICAL
CVSS 9.9 CRITICAL CWE-1336 Published 2026-05-29 PoCs 2 ★ 1 Last push 2026-10-03 (1 week ago)

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

Show 2 repositories
covepseng/cve-2026-9558-poc

Exploitability PoC for CVE-2026-9558 (SSTI Mautic Theme)

★ 1 · 2026-07-12
CVE-2026-88773
CRITICAL
CVSS 9.3 CRITICAL CWE-444 Published 2026-09-27 PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23.

Show 1 repositories
Scyrix-LLC/CVE-2026-88773

CVE-2026-88773

★ 0 · 2026-10-02
CVE-2026-94541
CRITICAL
CVSS 9.8 CRITICAL CWE-862 Published 2026-10-02 PoCs 1 ★ 0 Last push 2026-10-02 (1 week ago)

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the push queue by the mail-to-push feature, and use those URLs to take over the targeted accounts. This exploit chain requires the plugin's mail-to-push feature (wpmobile_auto_mail=1) to be enabled, as that setting is what causes outbound WordPress password-reset emails — including the reset URL and key — to be mirrored into the push row queue where they become accessible to the attacker.

Show 1 repositories
anoxhunterdump-ctrl/CVE-2026-94541-WPMobileApp-AuthBypass

Defensive analysis, detection scanner, and rule signatures for CVE-2026-94541 (WPMobile.App <= 11.82).

★ 0 · 2026-10-02
CVE-2026-90817
CRITICALMULTI PoC
CVSS 9.8 CRITICAL CWE-73, CWE-94 Published 2026-09-20 PoCs 5 ★ 2 Last push 2026-10-01 (1 week, 1 day ago)

An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintended controller route from a public survey context and by supplying a crafted file-path/stream parameter during import handling. If successfully exploited, this could allow the attacker to remotely execute arbitrary code on the REDCap server. The attacker does not have to be authenticated in order to exploit this, but exploitation requires knowledge of a valid public survey hash. This vulnerability exists in REDCap 13.3.0 and higher.

Show 5 repositories
murrez/CVE-2026-90817

Unauth REDCap RCE (CVE-2026-90817) mass check PoC — requires public survey hash for full validation.

★ 2 · 2026-09-21
yulisec/CVE-2026-90817
★ 1 · 2026-09-24
securifera/CVE-2026-90817

REDCap DataImport RCE

★ 1 · 2026-10-01
ExDev994/CVE-2026-90817
★ 0 · 2026-09-21
Farih123/CVE-2026-90817
★ 0 · 2026-09-26
CVE-2026-93616
CRITICAL
CVSS 9.8 CRITICAL CWE-22 Published 2026-09-22 PoCs 2 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Show 2 repositories
WadesWeaponShed/CVE-2026-93616_Checks

Simple Checks to look for indicators of compromise

★ 0 · 2026-09-22
BishopFox/CVE-2026-93616-check

Safely detect Check Point CPM RCE CVE-2026-93616

★ 0 · 2026-10-01
CVE-2026-92966
CRITICAL
CVSS 9.1 CRITICAL CWE-94 Published 2026-10-01 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The payload is planted during the unauthenticated booking flow and triggered when the Customer Cabinet block rendered by render_customer_dashboard() outputs the stored name into the content stream, where WordPress core's do_shortcode filter at priority 11 re-parses and executes it.

Show 1 repositories
murrez/CVE-2026-92966

CVE-2026-92966 — WordPress LatePoint ≤5.7.0 unauthenticated stored shortcode execution (CVSS 9.1, CWE-94). PoCbit mass-exploit PoC: plant [caption]/custom shor…

★ 0 · 2026-10-01
CVE-2026-96349
CRITICAL
CVSS 10.0 CRITICAL CWE-94 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.

Show 1 repositories
murrez/CVE-2026-96349

CVE-2026-96349 — WordPress SiteSkite plugin ≤2.1.8 unauthenticated RCE (CVSS 10.0, CWE-94). PoCbit mass-exploit PoC: legacy API-key autologin (?token=) + REST …

★ 0 · 2026-10-01
CVE-2026-96760
CRITICAL
CVSS 9.8 CRITICAL CWE-20, CWE-347, CWE-358, CWE-670 Published 2026-09-28 PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

Show 1 repositories
uziii2208/CVE-2026-96760

Authlib 1.7.2: Signature Verification Bypass - General JSON JWS Accepts Unsigned Payload when `signatures` is Empty

★ 0 · 2026-09-30
CVE-2026-88772
CRITICAL
CVSS 9.5 CRITICAL CWE-119 Published 2026-09-27 PoCs 3 ★ 13 Last push 2026-09-29 (1 week, 3 days ago)

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

Show 3 repositories
murrez/CVE-2026-88772

CVE-2026-88772 PoC: Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS, CVSS 9.5). Fingerprints Gateway, build vs 14.1-73.37 / 13.1-64.23, UDP/443 DTLS…

★ 13 · 2026-09-27
FollowerSeize/CVE-2026-88772-POC

CVE-2026-88772 - Citrix NetScaler ADC/Gateway DTLS memory overflow (RCE/DoS)

★ 0 · 2026-09-28
CVE-2026-97163
CRITICAL
CVSS 10.0 CRITICAL CWE-22, CWE-284 Published 2026-09-26 PoCs 2 ★ 1 Last push 2026-09-27 (1 week, 6 days ago)

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Show 2 repositories
murrez/CVE-2026-97163

CVE-2026-97163 PoC: Joomla UP (lomart.fr) unauthenticated GitHub mini-install / remote action deployment (≤6.0.29). Detects plugin version, probes com_ajax ins…

★ 1 · 2026-09-26
kize7/cve-2026-97163-payload

CVE-2026-97163 PoC payload (UP plugin Joomla remote code installation)

★ 0 · 2026-09-27
CVE-2026-97161
CRITICAL
CVSS 9.2 CRITICAL CWE-22, CWE-284 Published 2026-09-26 PoCs 1 ★ 0 Last push 2026-09-26 (1 week, 6 days ago)

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Show 1 repositories
murrez/CVE-2026-97161

CVE-2026-97161 PoC: Joomla UP (lomart.fr) unauthenticated path traversal / arbitrary file read via ajax-view (≤6.0.29). Fingerprints plugin, probes configurati…

★ 0 · 2026-09-26
CVE-2026-97160
CRITICAL
CVSS 9.4 CRITICAL CWE-94 Published 2026-09-26 PoCs 1 ★ 1 Last push 2026-09-26 (1 week, 6 days ago)

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Show 1 repositories
murrez/CVE-2026-97160

CVE-2026-97160 PoC for Joomla UP (lomart.fr): privileged {up php=} shortcode eval code injection in versions 5.0.0–5.2.0 and 6.0.0–6.0.29 (fix 5.2.1 / 6.1.0). …

★ 1 · 2026-09-26
CVE-2026-94132
CRITICAL
CVSS 9.5 CRITICAL CWE-434 Published 2026-09-26 PoCs 1 ★ 1 Last push 2026-09-26 (1 week, 6 days ago)

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, so anyone who could email the monitored mailbox could write a PHP file into the web root.

Show 1 repositories
murrez/CVE-2026-94132

AcyMailing Enterprise for Joomla < 11.1.0: POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE when an …

★ 1 · 2026-09-26
Page 1 / 3 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.