Files
CVEs-PoC/README.md
T
2026-04-21 06:33:16 +00:00

17 KiB
Raw Blame History

Recently updated Proof-of-Concepts

2026

Latest 20 of 91 Repositories

Stars Updated Name Description
258 1 day ago CVE-2026-21858 n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)
203 3 days ago CVE-2026-24061 Exploitation of CVE-2026-24061
66 3 days ago CVE-2026-24061-POC
26 11 days ago cve-2026-32746 CVE-2026-32746 - GNU InetUtils telnetd LINEMODE SLC Buffer Overflow PoC (pre-auth RCE, CVSS 9.8)
39 8 days ago CVE-2026-25769 Remote Code Execution via Insecure Deserialization in Wazuh Cluster
29 15 days ago CVE-2026-1731 CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash arithmetic evaluation in a WebSocket-reachable script
8 66 days ago Ashwesker-CVE-2026-21509 CVE-2026-21509
21 10 days ago CVE-2026-21852-PoC
16 17 days ago CVE-2026-21509-PoC Educational PoC for CVE202621509 (Microsoft Office security feature bypass). Generates a harmless DOCX with dummy OLE artifacts to study EDR/AV visibility. Not an exploit. For isolated labs only; see README for 7Zip inspection steps and mitigation references.
33 9 days ago CVE-2026-22812-exploit
16 6 days ago CVE-2026-21643 CVE-2026-21643
31 29 days ago CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE
11 7 days ago CVE-2026-5201 CVE-2026-5201: Heap-based buffer overflow in gdk-pixbuf JPEG loader (CWE-122, CVSS 7.5)
21 75 days ago CVE-2026-23745 Proof of Concept for CVE-2026-23745: Arbitrary File Overwrite vulnerability in node-tar (versions < 7.5.3).
5 8 days ago Ashwesker-CVE-2026-21962 CVE-2026-21962
17 1 day ago CVE-2026-0740 Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload
8 3 days ago CVE-2026-24061 CVE-2026-24061 Batch Scanning Tool
9 3 days ago CVE-2026-24061
7 5 days ago langflow-CVE-2026-33017-poc CVE-2026-33017 - An unauthenticated remote code execution in Langflow <= 1.8.1 via Public Flow Build Endpoint
5 3 days ago CVE-2026-24061-POC CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.

2025

Latest 20 of 564 Repositories

Stars Updated Name Description
1401 5 hours ago CVE-2025-55182 Explanation and full RCE PoC for CVE-2025-55182
795 16 days ago CVE-2025-55182-research CVE-2025-55182 POC
697 15 hours ago CVE-2025-33073 PoC Exploit for the NTLM reflection SMB flaw.
521 1 day ago CVE-2025-32463_chwoot Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
457 15 hours ago CVE-2025-32463 Local Privilege Escalation to Root via Sudo chroot in Linux
312 6 days ago CVE-2025-53770-Exploit SharePoint WebPart Injection Exploit Tool
312 4 days ago CVE-2025-55182 RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension CVE-2025-55182 & CVE-2025-66478
1034 6 days ago React2Shell-CVE-2025-55182-original-poc Original Proof-of-Concepts for React2Shell CVE-2025-55182
401 1 day ago CVE-2025-24071_PoC CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
213 19 hours ago CVE-2025-32023 PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"
276 18 hours ago CVE-2025-55182-advanced-scanner-
418 1 day ago Next.js-RSC-RCE-Scanner-CVE-2025-66478 A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
386 7 days ago ColorOS-CVE-2025-10184 ColorOS短信漏洞,以及用户自救方案
189 1 day ago POC-CVE-2025-24813 his repository contains an automated Proof of Concept (PoC) script for exploiting CVE-2025-24813, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
190 26 days ago RSC-Detect-CVE-2025-55182 RSC Detect CVE 2025 55182
198 12 days ago CVE-2025-30208-EXP CVE-2025-30208-EXP
158 2 days ago CVE-2025-21756 Exploit for CVE-2025-21756 for Linux kernel 6.6.75. My first linux kernel exploit!
172 18 days ago CVE-2025-26125 ( 0day ) Local Privilege Escalation in IObit Malware Fighter
190 14 hours ago CVE-2025-32756-POC Proof of Concept for CVE-2025-32756 - A critical stack-based buffer overflow vulnerability affecting multiple Fortinet products.
110 17 hours ago CVE-2025-43300 This is POC for IOS 0click CVE-2025-43300

2024

Latest 20 of 618 Repositories

Stars Updated Name Description
2445 23 minutes ago CVE-2024-1086 Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu, and KernelCTF. The success rate is 99.4% in KernelCTF images.
692 4 days ago CVE-2024-38063 poc for CVE-2024-38063 (RCE in tcpip.sys)
492 8 days ago cve-2024-6387-poc a signal handler race condition in OpenSSH's server (sshd)
515 36 days ago CVE-2024-49113 LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113
519 1 day ago CVE-2024-6387_Check CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH
224 5 hours ago CVE-2024-38077 RDL的堆溢出导致的RCE
382 11 days ago cve-2024-6387-poc 32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc
332 4 days ago CVE-2024-0044 CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13
312 15 days ago CVE-2024-4577 PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC
318 4 days ago CVE-2024-21338 Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.
235 3 days ago CVE-2024-21413 CVE-2024-21413 PoC for THM Lab
763 11 days ago CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability Microsoft-Outlook-Remote-Code-Execution-Vulnerability
9 39 days ago CVE-2024-38077-POC
179 1 day ago CVE-2024-6387 Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
238 15 days ago CVE_2024_30078_POC_WIFI basic concept for the latest windows wifi driver CVE
180 7 days ago CVE-2024-25600 Unauthenticated Remote Code Execution Bricks <= 1.9.6
203 63 days ago CVE-2024-23897 CVE-2024-23897
85 13 days ago CVE-2024-40725-CVE-2024-40898 CVE-2024-40725 and CVE-2024-40898, affecting Apache HTTP Server versions 2.4.0 through 2.4.61. These flaws pose significant risks to web servers worldwide, potentially leading to source code disclosure and server-side request forgery (SSRF) attacks.
157 55 days ago CVE-2024-21413 Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC
140 97 days ago cve-2024-20017 exploits for CVE-2024-20017

2023

Latest 20 of 521 Repositories

Stars Updated Name Description
788 31 days ago CVE-2023-38831-winrar-exploit CVE-2023-38831 winrar exploit generator
375 1 day ago CVE-2023-32233 CVE-2023-32233: Linux内核中的安全漏洞
506 7 days ago Windows_LPE_AFD_CVE-2023-21768 LPE exploit for CVE-2023-21768
416 22 days ago CVE-2023-0386 CVE-2023-0386在ubuntu22.04上的提权
113 33 days ago CVE-2023-21839 Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
389 3 days ago CVE-2023-4911 PoC for CVE-2023-4911
283 39 days ago CVE-2023-21608 Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
318 14 days ago CVE-2023-4863
243 17 days ago CVE-2023-44487 Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487
168 116 days ago CVE-2023-36745
244 11 hours ago CVE-2023-7028 This repository presents a proof-of-concept of CVE-2023-7028
347 198 days ago CVE-2023-23397-POC-Powershell
228 13 days ago CVE-2023-3519 RCE exploit for CVE-2023-3519
231 59 days ago CVE-2023-20887 VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
180 53 days ago CVE-2023-28252
133 24 days ago CVE-2023-2640-CVE-2023-32629 GameOver(lay) Ubuntu Privilege Escalation
239 11 days ago Weblogic-CVE-2023-21839
209 7 days ago CVE-2023-46747-RCE exploit for f5-big-ip RCE cve-2023-46747
237 3 days ago CVE-2023-29357 Microsoft SharePoint Server Elevation of Privilege Vulnerability
170 98 days ago CVE-2023-25157 CVE-2023-25157 - GeoServer SQL Injection - PoC

2022

Latest 20 of 560 Repositories

Stars Updated Name Description
1127 7 days ago CVE-2022-0847-DirtyPipe-Exploit A root exploit for CVE-2022-0847 (Dirty Pipe)
579 2 days ago CVE-2022-23222 CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation
363 69 days ago CVE-2022-21907 HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
356 42 days ago CVE-2022-40684 A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
379 30 days ago CVE-2022-29464 WSO2 RCE (CVE-2022-29464) exploit and writeup.
708 11 hours ago CVE-2022-0847-DirtyPipe-Exploits A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
437 29 days ago CVE-2022-25636 CVE-2022-25636
488 40 days ago CVE-2022-2588 exploit for CVE-2022-2588
500 29 days ago CVE-2022-0995 CVE-2022-0995 exploit
416 5 days ago CVE-2022-33679 One day based on https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
388 18 days ago CVE-2022-39197 CobaltStrike <= 4.7.1 RCE
280 11 days ago CVE-2022-0847 CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
352 5 days ago CVE-2022-21894 baton drop (CVE-2022-21894): Secure Boot Security Feature Bypass Vulnerability
378 41 days ago CVE-2022-0185 CVE-2022-0185
542 21 hours ago CVE-2022-38694_unlock_bootloader This is a one-time signature verification bypass. For persistent signature verification bypass, check https://github.com/TomKing062/CVE-2022-38691_38692
283 7 days ago cve-2022-27255
265 15 days ago CVE-2022-39952 POC for CVE-2022-39952
240 13 days ago CVE-2022-20699 Cisco Anyconnect VPN unauth RCE (rwx stack)
221 24 days ago CVE-2022-34918 CVE-2022-34918 netfilter nf_tables 本地提权 POC
233 21 days ago CVE-2022-30075 Tp-Link Archer AX50 Authenticated RCE (CVE-2022-30075)