| Stars |
Updated |
Repository |
Description |
| 0⭐ |
1h ago |
CVE-2026-49777 |
Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for… |
| 0⭐ |
12h ago |
CVE-2025-24799 |
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection… |
| 0⭐ |
16h ago |
CVE-2026-64747 |
AppleAVE2 kernel driver wire-format research and macOS reachability PoC for CVE-2026-64747. |
| 0⭐ |
17h ago |
POC-CVE-2025-68613 |
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4,… |
| 0⭐ |
17h ago |
CVE-2025-4255---Buffer-Overflow |
Exploit Framework for CVE-2025-4255 |
| 2⭐ |
19h ago |
CVE-2026-58138 |
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that… |
| 0⭐ |
1d ago |
CVE-2025-29927-PoC |
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior… |
| 1⭐ |
1d ago |
CVE-2026-32475 |
CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE |
| 0⭐ |
1d ago |
Langflow-RCE-CVE-2025-3248 |
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A… |
| 2⭐ |
1d ago |
CVE-2025-9974 |
Proof of Concept code for the CVE-2025-9974 affecting Nokia Beacon routers. |
| Stars |
Updated |
Repository |
Description |
| 4⭐ |
4h ago |
CVE-2026-41091-PoC-Exploit |
CVE-2026-41091 RedSun / Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via… |
| 5⭐ |
1d ago |
xiaomi15-dada-cve-2026-64560 |
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8 |
| 5⭐ |
1d ago |
cve-2026-32475-elementor-pro-lab |
A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via… |
| 5⭐ |
1d ago |
CVE-2026-15409-15410-Framework |
CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features:… |
| 3⭐ |
3d ago |
CVE-2026-62735 |
Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM… |
| 10⭐ |
3d ago |
CVE-2026-19490 |
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause… |
| 3⭐ |
6d ago |
CVE-2026-78904-Digital-Dinar-Drain |
CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central… |
| 16⭐ |
7d ago |
givewp-cve-2026-82222-rce-lab |
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix. |
| 3⭐ |
7d ago |
PaperCut-CVE-2026-81578-82078 |
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078 |
| 21⭐ |
10d ago |
CVE-2026-62735 |
CVE 1-day in http.sys |
| 20⭐ |
10d ago |
CVE-2026-72898 |
Metabase SQLi |
| 4⭐ |
10d ago |
CVE-2026-19478 |
GitLab Code injection |
| 3⭐ |
10d ago |
CVE-2026-21962 |
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion… |
| 4⭐ |
11d ago |
CVE-2026-73570 |
Zimbra SNMP Notification OS Command Injection - Unauthenticated RCE via SMTP exploit (Poc) |
| 88⭐ |
11d ago |
CVE-2026-75604-poc |
CVE-2026-75604 Next.js Windows RCE poc |
| 5⭐ |
11d ago |
CVE-2026-73570 |
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional… |
| 3⭐ |
12d ago |
CVE-2026-32475-PoC |
PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python. |
| 13⭐ |
12d ago |
Keycloak_CVE-2026-18963_PoC |
This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...). |
| 19⭐ |
12d ago |
CVE-2026-18963-keycloak |
A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine… |
| 4⭐ |
12d ago |
CVE-2026-20079 |
Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center. |
| Stars |
Updated |
Repository |
Description |
| 6⭐ |
10d ago |
vivo_iqoo_neo_9_root_research_on_CVE-2025-21479 |
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of… |
| 4⭐ |
17d ago |
cve-2025-21479_iqooneo8 |
Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables… |
| 20⭐ |
26d ago |
CVE-2025-7771 |
ThrottleStop.sys Arbitrary Physical Memory R/W |
| 6⭐ |
30d ago |
CVE-2025-8045 |
Dirty Pagetable Exploit for CVE-2025-8045 |
| 7⭐ |
35d ago |
SELinux-Permissive-Only-CVE-2025-21479 |
This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the… |
| 4⭐ |
46d ago |
CVE-2025-32432 |
Exploit, POC for CVE-2025-32432, CraftCMS2Shell |
| 4⭐ |
49d ago |
CVE-2025-64512 |
CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads |
| 5⭐ |
50d ago |
CVE-2025-8110-gogs-poc |
PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink |
| 7⭐ |
60d ago |
CVE-2025-30065 |
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It… |
| 4⭐ |
65d ago |
CVE-2025-69212-PoC |
OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M… |
| 3⭐ |
65d ago |
CVE-2025-57819 |
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE) |
| 4⭐ |
70d ago |
CVE-2025-69212-PoC |
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and… |
| 5⭐ |
72d ago |
CVE-2025-8110 |
PoC exploit for CVE-2025-8110 |
| 14⭐ |
86d ago |
vulnerable-nextjs-14-CVE-2025-29927 |
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior… |
2024, 2023, 2022
| Stars |
Updated |
Repository |
Description |
| 16⭐ |
20d ago |
CVE-2024-56426 |
A PoC of the CVE-2024-56426 vulnerability. |
| 3⭐ |
22d ago |
CVE-2024-56426 |
CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F |
| 3⭐ |
38d ago |
CVE-2024-36104-PoC |
PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path… |
| 3⭐ |
77d ago |
CVE-2024-36991 |
Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed. |
| 7⭐ |
86d ago |
CVE-2024-27983-nodejs-http2 |
CVE-2024-27983 this repository builds up a vulnerable HTTP2 Node.js server (server-nossl.js) based on… |
| Stars |
Updated |
Repository |
Description |
| 3⭐ |
41d ago |
CVE-2023-52076-PoC |
PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary… |
| 5⭐ |
45d ago |
CVE-2023-36003 |
PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender. |
| 3⭐ |
60d ago |
cve-2023-4911-exploit-optimized |
Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing… |
| 15⭐ |
62d ago |
CVE-2023-32315-EXPLOIT |
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass |
| 6⭐ |
78d ago |
CVE-2023-6019 |
PoC exploit for CVE-2023-6019 - Remote Code Execution via unauthenticated Ray Dashboard Jobs API. |
Every file is plain JSON on the CDN. No key, no rate limit.
# everything the index knows about one CVE
curl -s https://pocindex.io/CVE_list.json \
| jq '.[] | select(.cve == "CVE-2021-44228") | {cve, poc: (.poc | length), nuclei, msf, edb, vulhub, collections}'
# every published CVSS assessment plus vetted advisory links
curl -s https://pocindex.io/cve_metadata.json | jq '."CVE-2021-44228"'
# likelihood of exploitation in the next 30 days
curl -s https://pocindex.io/epss.json | jq '."CVE-2021-44228"'
# stars and last push for one PoC repository; repository keys are lowercased
curl -s https://pocindex.io/repo_meta.json | jq '."sfewer-r7/cve-2026-55040"'
What CISA says is being exploited, that also has a PoC here, ranked by how
likely each is to be used next:
curl -s https://pocindex.io/kev.json -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
'[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
| sort_by(-.epss) | .[:10]'
| Endpoint |
Holds |
CVE_list.json |
Every CVE with a linked PoC, its description and its poc, nuclei, msf, edb, vulhub and collections links |
cve_metadata.json |
NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links |
epss.json |
Exploitation probability and percentile, for nearly every CVE indexed |
nuclei.json |
Template metadata for the CVEs covered by a runnable Nuclei check |
kev.json |
CISA known exploited, keyed by CVE id |
repo_meta.json |
Stars and last push date per PoC repository, keys lowercased |
trending_poc.json |
Trending repositories plus index totals |
cves/2026/CVE-2026-68138.md |
Markdown copy of one CVE, one directory per year |
CVSS rows are [version, score, severity, vector, source, assessment type].
Advisory rows are [URL, NVD reference tags].
| Source |
What it contributes |
| GitHub |
Repositories naming a CVE, checked for code before they are linked |
| PoC-in-GitHub |
Historical repository candidates, passed through the same code and intent checks |
| Nuclei |
Runnable templates that exercise the vulnerability |
| ExploitDB |
Archived exploits, mapped by their own CVE column |
| Metasploit |
Modules, best ranked first |
| Vulhub |
Runnable vulnerable environments and reproduction steps |
| afrog, Vulnerability, 0day, xray |
CVE-specific templates, code and reproduction guides inside multi-CVE repositories |
| EPSS |
Daily exploitation probability from FIRST |
| CISA KEV |
What is being exploited in the wild |
| NVD |
CVSS assessments and tagged vendor, third-party, patch and mitigation references |
| CVE Program |
The CVE record, publication state and CNA references |
| Job |
Cadence |
Picks up |
| Trending sweep |
hourly |
Front-page repositories and prior-hour candidates added to the searchable index |
| CVE sync |
daily |
New CVEs, CNA references and recently pushed GitHub repositories for every CVE year |
| Metadata sync |
daily plus weekly full pass |
CVSS, advisories, rejected records and current CISA KEV status |
| Nuclei sync |
daily |
New templates and rating changes |
| Exploit archives |
daily |
ExploitDB, Metasploit and Vulhub mappings |
| Historical GitHub sync |
weekly |
Older PoC repositories missed by the recent-push window |
| Path collection sync |
weekly |
CVE-specific artifacts inside curated multi-CVE repositories |
| Link audit |
weekly |
Repositories that went dead, dropped from the index |
Missing PoC, wrong link, dead repository: open an issue with the CVE id and the
repository URL.