
TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things
all Top Top Top_Codeql TOP All bugbounty pentesting CVE-2022- POC Exp Things
| star | updated_at | name | url | des |
|---|---|---|---|---|
| 4075 | 2026-09-29T18:13:27Z | copy-fail-CVE-2026-31431 | https://github.com/theori-io/copy-fail-CVE-2026-31431 | Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code |
| 784 | 2026-09-30T00:41:22Z | wp2shell-poc | https://github.com/Icex0/wp2shell-poc | wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain |
| 184 | 2026-09-22T21:10:42Z | next-16.2.4-pocs | https://github.com/dwisiswant0/next-16.2.4-pocs | Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572) |
| 1242 | 2026-09-30T03:05:55Z | ghostlock-app | https://github.com/YuKongA/ghostlock-app | GhostLock One-Tap Execution App (CVE-2026-43499) |
| 962 | 2026-09-29T05:15:07Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 576 | 2026-09-17T06:14:13Z | cve_2026_31431 | https://github.com/rootsecdev/cve_2026_31431 | Exploit POC for CVE_2026_31431 |
| 565 | 2026-09-26T16:05:39Z | wp2shell-PoC | https://github.com/arvindear/wp2shell-PoC | CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept |
| 331 | 2026-09-30T03:20:27Z | CVE-2026-54121 | https://github.com/aniqfakhrul/CVE-2026-54121 | Certighost POC |
| 246 | 2026-09-25T21:18:15Z | CVE-2026-43499-popsicle | https://github.com/x-spy/CVE-2026-43499-popsicle | CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k |
| 231 | 2026-09-20T20:12:00Z | CVE-2026-41089 | https://github.com/0xABCD01/CVE-2026-41089 | Netlogon and CLDAP vulnerability research with a proof of concept. |
| 303 | 2026-09-28T08:18:46Z | CVE-2026-21858 | https://github.com/Chocapikk/CVE-2026-21858 | n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0) |
| 1315 | 2026-09-30T02:36:29Z | Root-My-Galaxy | https://github.com/BuSung-dev/Root-My-Galaxy | KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499 |
| 261 | 2026-09-28T02:20:04Z | CVE-2026-40369-EXPLOIT | https://github.com/orinimron123/CVE-2026-40369-EXPLOIT | Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox |
| 208 | 2026-09-11T02:48:30Z | CVE-2026-24061 | https://github.com/SafeBreach-Labs/CVE-2026-24061 | Exploitation of CVE-2026-24061 |
| 160 | 2026-09-26T04:26:40Z | CVE-2026-43499 | https://github.com/MobiusM/CVE-2026-43499 | CVE-2026-43499 PoC |
| 359 | 2026-09-23T10:28:19Z | copyfail-go | https://github.com/badsectorlabs/copyfail-go | A Go implementation of copyfail (CVE-2026-31431) |
| 182 | 2026-09-29T04:12:12Z | CVE-2026-62911 | https://github.com/hypnguyen1209/CVE-2026-62911 | POC pre-auth RCE on Exchange |
| 110 | 2026-09-23T12:37:51Z | wp2shell | https://github.com/0xsha/wp2shell | CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core |
| 825 | 2026-09-26T15:54:26Z | CVE-2026-24061 | https://github.com/jacubes/CVE-2026-24061 | CVE-2026-24061 exploit PoC |
| 141 | 2026-09-24T18:40:10Z | CVE-2026-42980-POC | https://github.com/G4sp4rCS/CVE-2026-42980-POC | CVE-2026-42980 PUBLIC EXPLOIT + RESEARCH |
| 505 | 2026-09-30T00:41:14Z | cPanelSniper | https://github.com/ynsmroztas/cPanelSniper | CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection |
| 409 | 2026-09-29T07:18:38Z | Root-My-Pixel | https://github.com/alex193a/Root-My-Pixel | Jailbreak supported Google Pixel phones with CVE-2026-43499 |
| 430 | 2026-09-30T02:23:38Z | LSPromise | https://github.com/LSPosed/LSPromise | Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284 |
| 102 | 2026-09-25T12:06:37Z | CVE-2026-75604-poc | https://github.com/rafabd1/CVE-2026-75604-poc | CVE-2026-75604 Next.js Windows RCE poc |
| 219 | 2026-09-24T15:41:52Z | ResetNightmare | https://github.com/Semperis-Community/ResetNightmare | POC tool for ResetNightmare (CVE-2026-27912) |
| 54 | 2026-09-27T21:53:28Z | samsung-android-lpe | https://github.com/Vikramaditya015/samsung-android-lpe | Poc for CVE-2026-20980, CVE-2026-20981, CVE-2026-20982 |
| 66 | 2026-09-23T13:49:05Z | wp2shell-scanner | https://github.com/ZephrFish/wp2shell-scanner | CVE-2026-63030, CVE-2026-60137, wp2shell scanner |
| 129 | 2026-09-24T18:06:13Z | CVE-2026-20817 | https://github.com/oxfemale/CVE-2026-20817 | Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service. |
| 374 | 2026-09-30T02:22:15Z | ghostlock-oneplus | https://github.com/JoinChang/ghostlock-oneplus | GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader |
| 124 | 2026-09-17T13:21:31Z | CVE-2026-41651 | https://github.com/Vozec/CVE-2026-41651 |
| star | updated_at | name | url | des |
|---|---|---|---|---|
| 1429 | 2026-09-28T12:48:24Z | CVE-2025-55182 | https://github.com/msanft/CVE-2025-55182 | Explanation and full RCE PoC for CVE-2025-55182 |
| 2452 | 2026-09-25T12:05:45Z | react2shell-scanner | https://github.com/assetnote/react2shell-scanner | High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) |
| 792 | 2026-09-17T03:00:41Z | CVE-2025-55182-research | https://github.com/ejpir/CVE-2025-55182-research | CVE-2025-55182 POC |
| 493 | 2026-08-11T09:12:24Z | CVE-2018-20250 | https://github.com/WyAtu/CVE-2018-20250 | exp for https://research.checkpoint.com/extracting-code-execution-from-winrar |
| 720 | 2026-09-26T22:43:27Z | CVE-2025-33073 | https://github.com/mverschu/CVE-2025-33073 | PoC Exploit for the NTLM reflection SMB flaw. |
| 962 | 2026-09-29T05:15:07Z | BYOVD | https://github.com/BlackSnufkin/BYOVD | BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501). |
| 530 | 2026-09-29T05:01:51Z | CVE-2025-32463_chwoot | https://github.com/pr0v3rbs/CVE-2025-32463_chwoot | Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463 |
| 248 | 2026-09-28T18:08:15Z | IngressNightmare-PoC | https://github.com/hakaioffsec/IngressNightmare-PoC | This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974). |
| 344 | 2026-09-28T05:13:17Z | redis_exploit | https://github.com/raminfp/redis_exploit | CVE-2025-49844 (RediShell) |
| 477 | 2026-09-17T02:59:49Z | CVE-2025-32463 | https://github.com/kh4sh3i/CVE-2025-32463 | Local Privilege Escalation to Root via Sudo chroot in Linux |
| 267 | 2026-09-28T19:09:42Z | CVE-2025-48799 | https://github.com/Wh04m1001/CVE-2025-48799 | |
| 142 | 2026-09-17T03:00:41Z | Nextjs_RCE_Exploit_Tool | https://github.com/pyroxenites/Nextjs_RCE_Exploit_Tool | Exploit for CVE-2025-55182 & CVE-2025-66478 |
| 314 | 2026-09-25T12:05:22Z | CVE-2025-53770-Exploit | https://github.com/soltanali0/CVE-2025-53770-Exploit | SharePoint WebPart Injection Exploit Tool |