Every new exploit,
on the radar.

Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.

monitoring live
11105CVEs tracked
25995PoC repositories
8New in 24h
355PoC updated in 7 days
filters
Reset
All New Fresh PoC Hot Multi PoC Critical High

69 results

CVE-2026-24046
NEWHIGHFRESH PoC
CVSS 7.1 HIGH CWE-22, CWE-59 Published 2026-01-21 PoCs 1 ★ 0 Last push 2026-10-09 (14 hours, 37 minutes ago) Discovered 2026-10-09 14:08

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Show 1 repositories
Rem1L/cve-2026-24046-poc
★ 0 · 2026-10-09
CVE-2024-36774
NEWHIGHFRESH PoC
CVSS 7.2 HIGH CWE-434 Published 2024-06-06 PoCs 1 ★ 0 Last push 2026-10-09 (15 hours, 38 minutes ago) Discovered 2026-10-09 14:08

An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Show 1 repositories
CVE-2022-21812
NEWHIGHFRESH PoC
CVSS 7.8 HIGH Published 2022-08-18 PoCs 1 ★ 0 Last push 2026-10-09 (19 hours, 22 minutes ago) Discovered 2026-10-09 14:08

Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

Show 1 repositories
CVE-2017-14849
HIGHFRESH PoC
CVSS 7.5 HIGH CWE-22 Published 2017-09-28 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 36 minutes ago) Discovered 2026-10-09 03:16

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

Show 1 repositories
CyberCTF/vulhub-node-cve-2017-14849

Vulhub node/CVE-2017-14849: Node.js 8.5.0 Path Traversal (CVE-2017-14849), run with Isoloom

★ 0 · 2026-10-09
CVE-2018-8715
HIGHFRESH PoC
CVSS 8.1 HIGH CWE-287 Published 2018-03-15 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 39 minutes ago) Discovered 2026-10-09 03:16

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

Show 1 repositories
CyberCTF/vulhub-appweb-cve-2018-8715

Vulhub appweb/CVE-2018-8715: Appweb Digest Authentication Bypass (CVE-2018-8715), run with Isoloom

★ 0 · 2026-10-09
CVE-2021-39214
HIGHFRESH PoC
CVSS 8.1 HIGH CWE-444 Published 2021-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (20 hours, 43 minutes ago) Discovered 2026-10-09 03:16

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.

Show 1 repositories
CyberCTF/secdevlabs-golden-hat

secDevLabs Golden Hat Society: mitmproxy 5.3.0 request smuggling, CVE-2021-39214 (OWASP A06), run with Isoloom

★ 0 · 2026-10-09
CVE-2025-41249
NEWHIGHFRESH PoC
CVSS 7.5 HIGH CWE-285 Published 2025-09-16 PoCs 1 ★ 0 Last push 2026-10-09 (21 hours, 44 minutes ago) Discovered 2026-10-09 14:08

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .

Show 1 repositories
edwin/simulating-cve-2025-41249
★ 0 · 2026-10-09
CVE-2026-93834
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-416 Published 2026-09-25 PoCs 1 ★ 1 Last push 2026-10-09 (21 hours, 50 minutes ago)

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and code execution (VM escape) as the QEMU process user.

Show 1 repositories
suominen/CVE-2026-93834

Tracking the QEMU CVE-2026-93834 9pfs fid-path use-after-free guest-to-host escape

★ 1 · 2026-10-09
CVE-2021-30535
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-415 Published 2021-06-07 PoCs 1 ★ 0 Last push 2026-10-09 (22 hours, 24 minutes ago) Discovered 2026-10-09 03:16

Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Show 1 repositories
califio/icu4x-crubit-demo

C++ contact-list demo comparing vulnerable ICU4C 66.1 with ICU4X through Crubit (CVE-2021-30535).

★ 0 · 2026-10-09
CVE-2026-91940
HIGHFRESH PoC
CVSS 8.7 HIGH CWE-22 Published 2026-09-15 PoCs 1 ★ 0 Last push 2026-10-08 (1 day, 6 hours ago) Discovered 2026-10-09 03:16

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account.

Show 1 repositories
BiiTts/CVE-2026-91940-crawl4ai-Arbitrary-File-Write

CVE-2026-91940: arbitrary file write in crawl4ai <=0.9.2 via the untrusted-config gate (PDFContentScrapingStrategy image_save_dir). Analysis, reproduction harn…

★ 0 · 2026-10-08
CVE-2026-96451
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-639 Published 2026-10-03 PoCs 2 ★ 0 Last push 2026-10-07 (2 days, 10 hours ago)

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

Show 2 repositories
Nxploited/CVE-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

★ 0 · 2026-10-04
MRdark-ops/wpexploit-CVE-2026-96451

Privilege Escalation vulnerability

★ 0 · 2026-10-07
CVE-2026-93355
HIGHFRESH PoC
CVSS 7.6 HIGH CWE-1390 Published 2026-09-28 PoCs 1 ★ 0 Last push 2026-10-07 (2 days, 19 hours ago)

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the victim's role, including proxy_admin privileges, and permanently overwrite the victim's stored identity binding to retain persistent unauthorized access to administrative endpoints exposing API keys and user management.

Show 1 repositories
InertFluid/cve-2026-93355-lab

Benign, offline reproduction of CVE-2026-93355 — LiteLLM unverified-email JWT account takeover (runs LiteLLM's real code)

★ 0 · 2026-10-07
CVE-2026-87902
HIGHFRESH PoCMULTI PoC
CVSS 8.1 HIGH CWE-98 Published 2026-09-22 PoCs 26 ★ 38 Last push 2026-10-07 (2 days, 19 hours ago)

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Show 8 of 26 repositories
ressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned vulnerable l…

★ 38 · 2026-09-22
abraxas/CVE-2026-87902

CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion (conditional RCE)

★ 35 · 2026-10-07
dinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional RCE (WP 4…

★ 13 · 2026-09-23
tc4dy/CVE-2026-87902-Toolkit

CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create,…

★ 10 · 2026-09-27
vulpecuna/CVE-2026-87902

Unauthenticated RCE on Wordpress

★ 9 · 2026-09-23
tonydelouvre/CVE-2026-87902

XWP_RCE — CVE-2026-87902 Hacker Console

★ 4 · 2026-09-29
ynsmroztas/WPSniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

★ 3 · 2026-09-23
crowsec-edtech/CVE-2026-87902

Proof of concept for vulnerability CVE-2026-87902 in Wordpress

★ 3 · 2026-09-25
CVE-2026-96512
HIGHFRESH PoC
CVSS 7.8 HIGH CWE-863 Published 2026-09-23 PoCs 2 ★ 0 Last push 2026-10-07 (3 days, 2 hours ago)

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from the calling user. Because sudo is a setuid-root program, an unprivileged local user can set TZ to an extreme timezone offset to shift the authorization window by up to approximately 25 hours, causing expired rules to be treated as valid. This allows the user to execute commands outside the intended time window. Authentication is not bypassed; only the time-based authorization check is affected.

Show 2 repositories
abraxas/CVE-2026-96512

CVE-2026-96512 - sudo - High 7.8 - Authenticated LOCAL TZ=UTC+14 sudo -n /usr/bin/id - Local Privilege Escalation via Time-Window Bypass

★ 0 · 2026-10-07
CVE-2026-93485
HIGHFRESH PoC
CVSS 7.1 HIGH CWE-79 Published 2026-09-18 PoCs 4 ★ 63 Last push 2026-10-06 (4 days ago)

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.

Show 4 repositories
DeathShotXD/Comment2Shell

Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views the post…

★ 63 · 2026-10-06
686f6c61/POC-WP-CORE-CVE-2026-93485

Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verifica…

★ 1 · 2026-09-26
HORKimhab/CVE-2026-93485

CVE-2026-93485 - Draft or TODO

★ 0 · 2026-09-22
0xBlackash/CVE-2026-93485

CVE-2026-93485

★ 0 · 2026-09-22
CVE-2026-96940
HIGHFRESH PoC
CVSS 8.8 HIGH CWE-1390 Published 2026-10-02 PoCs 1 ★ 1 Last push 2026-10-06 (4 days, 2 hours ago)

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Show 1 repositories
HORKimhab/CVE-2026-96940

CVE-2026-96940

★ 1 · 2026-10-06
CVE-2026-96889
HIGHFRESH PoC
CVSS 7.8 HIGH CWE-416 Published 2026-09-23 PoCs 1 ★ 18 Last push 2026-10-05 (4 days, 7 hours ago)

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

Show 1 repositories
rafabd1/VectorFreed

This repository documents the VectorFreed RCE chain and includes a PoC for CVE-2026-96889.

★ 18 · 2026-10-05
CVE-2026-93687
HIGHFRESH PoC
CVSS 8.7 HIGH CWE-674 Published 2026-09-18 PoCs 2 ★ 0 Last push 2026-10-05 (4 days, 10 hours ago)

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Node.js process with an uncaught RangeError.

Show 2 repositories
scastillo-jp/braces-fork

Temporary fork of braces with a minimal security patch for CVE-2026-93687, created only to validate dependency override behavior and Fortify/FoD detection befo…

★ 0 · 2026-09-24
pillarsdotnet/node-braces

Ubuntu's node-braces plus the CVE-2026-93687 nesting-depth fix, for ppa:pillarsdotnet/ppa

★ 0 · 2026-10-05
CVE-2026-86950
HIGHFRESH PoCMULTI PoC
CVSS 8.8 HIGH CWE-787 Published 2026-09-28 PoCs 5 ★ 9 Last push 2026-10-05 (4 days, 15 hours ago)

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Show 5 repositories
msuiche/hotcell

Runtime exploit monitor for Apple document/image pipelines (iOS/macOS) — EXPMON concept: Frida agent + behavioral rules. First target: the CVE-2026-86950 glyph…

★ 9 · 2026-10-02
decalage2/detect_CVE-2026-86950

A python tool to detect PDF files exploiting CVE-2026-86950

★ 4 · 2026-10-02
DeAurity/CVE-2026-86950-POC

Out-of-bounds Write (CWE-787)

★ 2 · 2026-09-29
34zY/CVE-2026-86950
★ 0 · 2026-10-01
0xBlackash/CVE-2026-86950

CVE-2026-86950

★ 0 · 2026-10-05
CVE-2026-92592
HIGHFRESH PoC
CVSS 8.7 HIGH CWE-1336 Published 2026-09-16 PoCs 1 ★ 0 Last push 2026-10-03 (6 days, 21 hours ago)

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie via the license-shun endpoint and transplant the signed envelope into the redirect parameter; on a successful login, Craft validates the signature and renders the authenticated bytes as an unsandboxed Twig template, where Twig's map filter accepts a string callback and allows PHP system() to execute arbitrary operating-system commands as the web-server user. Exploitation requires an account using password authentication without active 2FA, the default request configuration, and availability of PHP system(). The issue is fixed in 4.18.6 and 5.10.13.

Show 1 repositories
godylockz/CVE-2026-92592

Proof of concept for CVE-2026-92592: Craft CMS authenticated RCE

★ 0 · 2026-10-03
CVSS 8.6 HIGH CWE-611 Published 2026-10-01 PoCs 1 ★ 0 Last push 2026-10-01 (1 week, 1 day ago)

Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to internal network locations via an external entity declaration in that document. The extension supplies its own Xalan-backed TransformerFactory to the xslt component and registers it as the JAXP default. Xalan-J 2.7.x predates JAXP 1.5 and does not honour javax.xml.XMLConstants.ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET, so the external access restrictions Apache Camel applies to the TransformerFactory it creates were not in effect. On the xslt component path this affects message bodies that reach the transformer already as a javax.xml.transform.Source; bodies of other types are converted to a SAXSource by Apache Camel with external entities and external DTD loading disabled, and are not affected. Because the factory is also the JAXP default, other code in the application obtaining one through TransformerFactory.newInstance() loses the same restrictions without error. Applications are affected if they use any of camel-quarkus-xslt, camel-quarkus-xslt-saxon, camel-quarkus-tika or camel-quarkus-xmlsecurity, each of which brings the XSLT support extension onto the classpath. For all but camel-quarkus-xslt, the exposure is limited to the JAXP default factory, since those extensions do not perform XSLT transformations themselves. Users are recommended to upgrade to version 3.33.3 or 3.40.0, which fixes this issue.

Show 1 repositories
oscerd/CVE-2026-88789

Reproducer for CVE-2026-88789 (Apache Camel Quarkus camel-quarkus-support-xalan drops the JAXP external access restrictions, XXE / SSRF) — Camel Quarkus

★ 0 · 2026-10-01
CVSS 7.2 HIGH CWE-79 Published 2026-09-30 PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.

Show 1 repositories
JailBr3ak/CVE-2026-97347
★ 0 · 2026-09-30
CVSS 8.8 HIGH CWE-89 Published 2026-09-28 PoCs 1 ★ 0 Last push 2026-09-30 (1 week, 2 days ago)

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Archiving Services Inc. EnVision allows SQL Injection. This issue affects enVision: before 260655.

Show 1 repositories
CVSS 8.5 HIGH CWE-77, CWE-78 Published 2026-09-20 PoCs 2 ★ 4 Last push 2026-09-28 (1 week, 4 days ago)

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

Show 2 repositories
HackSpeak/CVE-2026-93958

D-Link R95 (BE9500) DHMAPI SetTimeSettings command injection -> root RCE PoC (CVE-2026-93958); for authorized testing

★ 4 · 2026-09-20
murrez/CVE-2026-93958

CVE-2026-93958 PoC: D-Link R95 BE9500 DHMAPI SetTimeSettings NTPServer authenticated root command injection. DHMAPI login, RCE verify, mass bulk exploit mode, …

★ 0 · 2026-09-28
CVSS 7.0 HIGH CWE-444, CWE-863 Published 2026-09-10 PoCs 1 ★ 0 Last push 2026-09-27 (1 week, 5 days ago)

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.

Show 1 repositories
Boreas37/CVE-2026-88008-PoC

CVE-2026-88008 - Traefik (<=2.11.56 / <=3.7.12): a client-controlled h2c upgrade tunnels past routers and middleware (BasicAuth/ForwardAuth/IPAllowList), unaut…

★ 0 · 2026-09-27
Page 1 / 3 Next >

Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.