| Stars |
Updated |
Repository |
Description |
| 0⭐ |
4h ago |
Langflow-RCE-CVE-2025-3248 |
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A… |
| 0⭐ |
10h ago |
CVE-2026-86350 |
CVE-2026-86350 - Apache Tomcat - Critical 9.1 - Unauthenticated GET /header.jsp - HTTP/2 Request Header… |
| 0⭐ |
1d ago |
CVE-2025-9974 |
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows… |
| 0⭐ |
1d ago |
CVE-2025-39964 |
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent… |
| 1⭐ |
2d ago |
CVE-2025-7771 |
ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write… |
| 0⭐ |
2d ago |
CVE-2026-87902 |
CVE-2026-87902: PoC for WordPress's critical path traversal |
| 0⭐ |
2d ago |
CVE-2026-87902 |
An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable… |
| 2⭐ |
3d ago |
ghostlock-cve-2026-43499 |
CVE-2026-43499 (GhostLock) - Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting… |
| 1⭐ |
4d ago |
CVE-2026-77812 |
DJI Drone Cleartext Bluetooth Transmission of Wi-Fi PSK and Session UUID - Proof of Concept for… |
| 1⭐ |
4d ago |
CVE-2025-6325_CVE-2025-6327 |
CVE-2025-6325 + CVE-2025-6327 - King Addons for Elementor <= 51.1.36 DUAL EXPLOIT PoC (Unauthenticated… |
| Stars |
Updated |
Repository |
Description |
| 9⭐ |
21h ago |
CVE-2026-78306 |
DJI Drone DUML Command Injection over Bluetooth - Proof of Concept for CVE-2026-78306 |
| 4⭐ |
1d ago |
op13-cve-2026-64560 |
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by… |
| 14⭐ |
1d ago |
CVE-2026-0073-PoC-Exploit |
🔓 CVE-2026-0073 - Android ADB Wireless Debugging Auth Bypass (CVSS 8.8) / Zero-click TLS type confusion to… |
| 11⭐ |
1d ago |
watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127 |
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious… |
| 5⭐ |
2d ago |
CVE-2026-87902-Toolkit |
CVE-2026-87902 - WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7-7.1.1. / 2… |
| 35⭐ |
2d ago |
CVE-2026-84543 |
Technical disclosure and PoC for CVE-2026-84543, a macOS SMB kernel vulnerability |
| 9⭐ |
2d ago |
CVE-2026-87902 |
Unauthenticated RCE on Wordpress |
| 5⭐ |
2d ago |
CVE_2026_87902 |
Exploit pycve_2026_87902_scanner.py /tmp/local.txt --console |
| 4⭐ |
2d ago |
CVE-2026-94129 |
A POC for CVE-2026-94129 |
| 4⭐ |
2d ago |
CVE-2026-94128 |
POC for CVE-2026-94128 |
| 32⭐ |
3d ago |
CVE-2026-87902 |
CVE-2026-87902 - WordPress - WordPress Core - Critical 9.2 - Unauthenticated Local File Inclusion… |
| 3⭐ |
3d ago |
CVE-2026-23921 |
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-23921 |
| 31⭐ |
3d ago |
cve-2026-87902-poc |
PoC for CVE-2026-87902 - unauthenticated path traversal in WordPress page-template resolution (local PHP… |
| 825⭐ |
3d ago |
CVE-2026-24061 |
CVE-2026-24061 exploit PoC |
| 24⭐ |
4d ago |
CVE-2026-43786 |
Proof of concept for CVE-2026-43786, a local privilege escalation vulnerability in macOS CoreServices that… |
| 3⭐ |
5d ago |
CVE-2026-88854 |
CVE-2026-88854 - OrdaSoft Joomla Gallery unauth SQLi PoC (check / mass scan / EXTRACTVALUE read) |
| 6⭐ |
5d ago |
CVE-2026-28609-matroska-pcm-oob |
Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in… |
| 4⭐ |
5d ago |
CVE-2026-93958 |
D-Link R95 (BE9500) DHMAPI SetTimeSettings command injection -> root RCE PoC (CVE-2026-93958); for authorized… |
| 5⭐ |
6d ago |
CVE-2026-92229 |
CVE-2026-92229 - Forminator ≤1.57.2 unauth shortcode exec (current_url / quiz AJAX). Python 3 PoC. |
| 3⭐ |
6d ago |
CVE-2026-81294 |
CVE-2026-81294 - WordPress - Paul Ryan - Critical 9.8 - Unauthenticated GET /wp-login.php?external=oauth2 -… |
2024, 2023
| Stars |
Updated |
Repository |
Description |
| 17⭐ |
40d ago |
CVE-2024-56426 |
A PoC of the CVE-2024-56426 vulnerability. |
| 4⭐ |
42d ago |
CVE-2024-56426 |
CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F |
| 3⭐ |
58d ago |
CVE-2024-36104-PoC |
PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path… |
| Stars |
Updated |
Repository |
Description |
| 3⭐ |
61d ago |
CVE-2023-52076-PoC |
PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary… |
| 6⭐ |
65d ago |
CVE-2023-36003 |
PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender. |
| 4⭐ |
80d ago |
cve-2023-4911-exploit-optimized |
Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing… |
| 15⭐ |
82d ago |
CVE-2023-32315-EXPLOIT |
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass |
Every file is plain JSON on the CDN. No key, no rate limit.
# everything the index knows about one CVE
curl -s https://pocindex.io/CVE_list.json \
| jq '.[] | select(.cve == "CVE-2021-44228") | {cve, poc: (.poc | length), nuclei, msf, edb, vulhub, collections}'
# every published CVSS assessment plus vetted advisory links
curl -s https://pocindex.io/cve_metadata.json | jq '."CVE-2021-44228"'
# likelihood of exploitation in the next 30 days
curl -s https://pocindex.io/epss.json | jq '."CVE-2021-44228"'
# stars and last push for one PoC repository; repository keys are lowercased
curl -s https://pocindex.io/repo_meta.json | jq '."sfewer-r7/cve-2026-55040"'
What CISA says is being exploited, that also has a PoC here, ranked by how
likely each is to be used next:
curl -s https://pocindex.io/kev.json -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
'[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
| sort_by(-.epss) | .[:10]'
| Endpoint |
Holds |
CVE_list.json |
Every CVE with a linked PoC, its description and its poc, nuclei, msf, edb, vulhub and collections links |
cve_metadata.json |
NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links |
epss.json |
Exploitation probability and percentile, for nearly every CVE indexed |
nuclei.json |
Template metadata for the CVEs covered by a runnable Nuclei check |
kev.json |
CISA known exploited, keyed by CVE id |
repo_meta.json |
Stars and last push date per PoC repository, keys lowercased |
trending_poc.json |
Trending repositories plus index totals |
cves/2026/CVE-2026-68138.md |
Markdown copy of one CVE, one directory per year |
CVSS rows are [version, score, severity, vector, source, assessment type].
Advisory rows are [URL, NVD reference tags].
| Source |
What it contributes |
| GitHub |
Repositories naming a CVE, checked for code before they are linked |
| PoC-in-GitHub |
Historical repository candidates, passed through the same code and intent checks |
| Nuclei |
Runnable templates that exercise the vulnerability |
| ExploitDB |
Archived exploits, mapped by their own CVE column |
| Metasploit |
Modules, best ranked first |
| Vulhub |
Runnable vulnerable environments and reproduction steps |
| afrog, Vulnerability, 0day, xray |
CVE-specific templates, code and reproduction guides inside multi-CVE repositories |
| EPSS |
Daily exploitation probability from FIRST |
| CISA KEV |
What is being exploited in the wild |
| NVD |
CVSS assessments and tagged vendor, third-party, patch and mitigation references |
| CVE Program |
The CVE record, publication state and CNA references |
| Job |
Cadence |
Picks up |
| Trending sweep |
hourly |
Front-page repositories and prior-hour candidates added to the searchable index |
| CVE sync |
daily |
New CVEs, CNA references and recently pushed GitHub repositories for every CVE year |
| Metadata sync |
daily plus weekly full pass |
CVSS, advisories, rejected records and current CISA KEV status |
| Nuclei sync |
daily |
New templates and rating changes |
| Exploit archives |
daily |
ExploitDB, Metasploit and Vulhub mappings |
| Historical GitHub sync |
weekly |
Older PoC repositories missed by the recent-push window |
| Path collection sync |
weekly |
CVE-specific artifacts inside curated multi-CVE repositories |
| Link audit |
weekly |
Repositories that went dead, dropped from the index |
Missing PoC, wrong link, dead repository: open an issue with the CVE id and the
repository URL.