| Stars |
Updated |
Repository |
Description |
| 2⭐ |
1h ago |
ghostlock-cve-2026-43499 |
CVE-2026-43499 (GhostLock) - Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting… |
| 0⭐ |
10h ago |
CVE-2025-39964 |
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent… |
| 1⭐ |
1d ago |
CVE-2026-89026 |
PoC exploit and scanner for CVE-2026-89026, targeting the Issabel PBXAPI authentication vulnerability |
| 1⭐ |
1d ago |
CVE-2025-6325_CVE-2025-6327 |
CVE-2025-6325 + CVE-2025-6327 - King Addons for Elementor <= 51.1.36 DUAL EXPLOIT PoC (Unauthenticated… |
| 2⭐ |
1d ago |
CVE-2026-90817 |
Unauth REDCap RCE (CVE-2026-90817) mass check PoC - requires public survey hash for full validation. |
| 2⭐ |
2d ago |
CVE-2026-89274 |
PoC for CVE-2026-89274: unauthenticated arbitrary shortcode execution in WP Recipe Maker ≤10.8.1 via recipe… |
| 2⭐ |
2d ago |
CVE-2026-81294 |
CVE-2026-81294 - WordPress - Paul Ryan - Critical 9.8 - Unauthenticated GET /wp-login.php?external=oauth2 -… |
| 1⭐ |
2d ago |
Flowise-RCE-CVE-2025-59528 |
Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability… |
| 1⭐ |
2d ago |
Flowise-CVE-2025-58434-PasswordReset |
Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password… |
| 0⭐ |
3d ago |
CVE-2025-20260 |
First public PoC for CVE-2025-20260 (CVSS 9.8) - a ClamAV PDF-scanning buffer overflow, with core-dump… |
| Stars |
Updated |
Repository |
Description |
| 5⭐ |
14m ago |
CVE-2026-78306 |
DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within… |
| 19⭐ |
1d ago |
CVE-2026-43786 |
Proof of concept for CVE-2026-43786, a local privilege escalation vulnerability in macOS CoreServices that… |
| 3⭐ |
1d ago |
CVE-2026-94129 |
A POC for CVE-2026-94129 |
| 3⭐ |
1d ago |
CVE-2026-94128 |
POC for CVE-2026-94128 |
| 3⭐ |
1d ago |
CVE-2026-88854 |
CVE-2026-88854 - OrdaSoft Joomla Gallery unauth SQLi PoC (check / mass scan / EXTRACTVALUE read) |
| 5⭐ |
1d ago |
CVE-2026-28609-matroska-pcm-oob |
Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in… |
| 4⭐ |
2d ago |
CVE-2026-93958 |
D-Link R95 (BE9500) DHMAPI SetTimeSettings command injection -> root RCE PoC (CVE-2026-93958); for authorized… |
| 825⭐ |
2d ago |
CVE-2026-24061 |
CVE-2026-24061 exploit PoC |
| 3⭐ |
2d ago |
CVE-2026-92229 |
CVE-2026-92229 - Forminator ≤1.57.2 unauth shortcode exec (current_url / quiz AJAX). Python 3 PoC. |
| 3⭐ |
5d ago |
CVE-2026-55781-poc |
Unbounded memory allocation in NanaZip's UFS handler via an attacker-controlled fs_bsize field. |
| 16⭐ |
5d ago |
CVE-2026-83991-writeup-and-poc |
CVE-2026-83991: Windows Cloud Files access-check bypass |
| 5⭐ |
6d ago |
CVE-2026-12793 |
CVE-2026-12793 PoC - JetFormBuilder ≤3.6.2 unauth Register User / admin account creation |
| 3⭐ |
6d ago |
POC-AIOWPM-CVE-2026-19949 |
PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <=… |
| 3⭐ |
6d ago |
CVE-2026-12944 |
Langflow 1.10.0 urllib SSRF POC |
| 16⭐ |
8d ago |
CVE-2026-31694-POC |
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a… |
| 4⭐ |
8d ago |
CVE-2026-18963 |
Keycloak reset-credentials flow bypass |
| 4⭐ |
8d ago |
CVE-2026-73570 |
Zimbra SNMP Notification OS Command Injection - Unauthenticated RCE via SMTP exploit (Poc) |
| 7⭐ |
8d ago |
CVE-2026-42536-PoC |
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and… |
| 4⭐ |
9d ago |
CVE-2026-33439-Python-PoC |
Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization |
| 4⭐ |
9d ago |
cve-2026-85706-poc-exploit-gitlab |
cve-2026-85706-poc-exploit-gitlab |
2024, 2023
| Stars |
Updated |
Repository |
Description |
| 17⭐ |
36d ago |
CVE-2024-56426 |
A PoC of the CVE-2024-56426 vulnerability. |
| 4⭐ |
38d ago |
CVE-2024-56426 |
CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F |
| 3⭐ |
54d ago |
CVE-2024-36104-PoC |
PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path… |
| Stars |
Updated |
Repository |
Description |
| 3⭐ |
57d ago |
CVE-2023-52076-PoC |
PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary… |
| 6⭐ |
61d ago |
CVE-2023-36003 |
PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender. |
| 4⭐ |
76d ago |
cve-2023-4911-exploit-optimized |
Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing… |
| 15⭐ |
78d ago |
CVE-2023-32315-EXPLOIT |
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass |
Every file is plain JSON on the CDN. No key, no rate limit.
# everything the index knows about one CVE
curl -s https://pocindex.io/CVE_list.json \
| jq '.[] | select(.cve == "CVE-2021-44228") | {cve, poc: (.poc | length), nuclei, msf, edb, vulhub, collections}'
# every published CVSS assessment plus vetted advisory links
curl -s https://pocindex.io/cve_metadata.json | jq '."CVE-2021-44228"'
# likelihood of exploitation in the next 30 days
curl -s https://pocindex.io/epss.json | jq '."CVE-2021-44228"'
# stars and last push for one PoC repository; repository keys are lowercased
curl -s https://pocindex.io/repo_meta.json | jq '."sfewer-r7/cve-2026-55040"'
What CISA says is being exploited, that also has a PoC here, ranked by how
likely each is to be used next:
curl -s https://pocindex.io/kev.json -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
'[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
| sort_by(-.epss) | .[:10]'
| Endpoint |
Holds |
CVE_list.json |
Every CVE with a linked PoC, its description and its poc, nuclei, msf, edb, vulhub and collections links |
cve_metadata.json |
NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links |
epss.json |
Exploitation probability and percentile, for nearly every CVE indexed |
nuclei.json |
Template metadata for the CVEs covered by a runnable Nuclei check |
kev.json |
CISA known exploited, keyed by CVE id |
repo_meta.json |
Stars and last push date per PoC repository, keys lowercased |
trending_poc.json |
Trending repositories plus index totals |
cves/2026/CVE-2026-68138.md |
Markdown copy of one CVE, one directory per year |
CVSS rows are [version, score, severity, vector, source, assessment type].
Advisory rows are [URL, NVD reference tags].
| Source |
What it contributes |
| GitHub |
Repositories naming a CVE, checked for code before they are linked |
| PoC-in-GitHub |
Historical repository candidates, passed through the same code and intent checks |
| Nuclei |
Runnable templates that exercise the vulnerability |
| ExploitDB |
Archived exploits, mapped by their own CVE column |
| Metasploit |
Modules, best ranked first |
| Vulhub |
Runnable vulnerable environments and reproduction steps |
| afrog, Vulnerability, 0day, xray |
CVE-specific templates, code and reproduction guides inside multi-CVE repositories |
| EPSS |
Daily exploitation probability from FIRST |
| CISA KEV |
What is being exploited in the wild |
| NVD |
CVSS assessments and tagged vendor, third-party, patch and mitigation references |
| CVE Program |
The CVE record, publication state and CNA references |
| Job |
Cadence |
Picks up |
| Trending sweep |
hourly |
Front-page repositories and prior-hour candidates added to the searchable index |
| CVE sync |
daily |
New CVEs, CNA references and recently pushed GitHub repositories for every CVE year |
| Metadata sync |
daily plus weekly full pass |
CVSS, advisories, rejected records and current CISA KEV status |
| Nuclei sync |
daily |
New templates and rating changes |
| Exploit archives |
daily |
ExploitDB, Metasploit and Vulhub mappings |
| Historical GitHub sync |
weekly |
Older PoC repositories missed by the recent-push window |
| Path collection sync |
weekly |
CVE-specific artifacts inside curated multi-CVE repositories |
| Link audit |
weekly |
Repositories that went dead, dropped from the index |
Missing PoC, wrong link, dead repository: open an issue with the CVE id and the
repository URL.