Just landed
Stars
Updated
Repository
Description
2⭐
5h ago
CVE-2025-32432-exploit-by-P34NUT
Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail
0⭐
16h ago
CVE-2026-12793
The JetFormBuilder - Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation…
0⭐
19h ago
lenovo_y700_tb320fc_on_CVE-2025-21479
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of…
1⭐
20h ago
CVE-2025-57231
Docmost < 0.22.0 - Arbitrary File Read
0⭐
1d ago
Langflow-RCE-CVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A…
1⭐
1d ago
langflow-CVE-2026-17633-PoC
PoC for CVE-2026-17633 - Authenticated RCE in IBM Langflow OSS 1.0.0-1.10.3 via custom_component endpoint.…
0⭐
1d ago
CVE-2025-24813
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure…
0⭐
2d ago
CVE-2025-64512_PoC
Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from…
0⭐
2d ago
CVE-2026-69328
Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
0⭐
2d ago
CVE-2025-32432
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond.…
Trending in 2026
Stars
Updated
Repository
Description
15⭐
12h ago
CVE-2026-83991-writeup-and-poc
CVE-2026-83991: Windows Cloud Files access-check bypass
180⭐
18h ago
cve-2026-41940-PoC
A cPanel and WHM authentication bypassing tool
3⭐
1d ago
POC-AIOWPM-CVE-2026-19949
PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <=…
3⭐
1d ago
CVE-2026-12944
Langflow 1.10.0 urllib SSRF POC
16⭐
2d ago
CVE-2026-31694-POC
Linux kernel FUSE readdir cache out-of-bounds write (CVE-2026-31694): a malicious FUSE server overflows a…
4⭐
3d ago
CVE-2026-18963
Keycloak reset-credentials flow bypass
4⭐
3d ago
CVE-2026-73570
Zimbra SNMP Notification OS Command Injection - Unauthenticated RCE via SMTP exploit (Poc)
7⭐
3d ago
CVE-2026-42536-PoC
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and…
3⭐
4d ago
cve-2026-85706-poc-exploit-gitlab
cve-2026-85706-poc-exploit-gitlab
3⭐
4d ago
CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker…
4⭐
4d ago
CVE-2026-78006-POC
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code…
4⭐
5d ago
CVE-2026-89013
CVE-2026-89013 Exploit - Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated…
5⭐
5d ago
CVE-2026-89012
CVE-2026-89012 Exploit - SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution…
3⭐
5d ago
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute…
9⭐
5d ago
CVE-2026-85706
GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC
35⭐
5d ago
cve-2026-85706
Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions:…
28⭐
5d ago
CVE-2026-54121-PoC-Exploit
CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework / Advanced toolkit with rogue DC/LDAP…
6⭐
5d ago
CVE-2026-24061-PoC-Exploit
️ CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control with CRLF injection via…
3⭐
7d ago
CVE-2026-11387-WooCommerce-SMS-OTP
SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert…
5⭐
8d ago
CVE-2026-19089-WooCommerce-Tyche
CVE-2026-19089 WooCommerce Tych Remote Command Execution
Trending in 2025
Stars
Updated
Repository
Description
3⭐
20d ago
CVE-2025-3248-Langflow-RCE
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A…
7⭐
21d ago
vivo_iqoo_neo_9_root_research_on_CVE-2025-21479
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of…
4⭐
28d ago
cve-2025-21479_iqooneo8
Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables…
3⭐
30d ago
vivo_iqoo_neo_9_root_research_on_CVE-2025-21479
iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** - 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案
20⭐
37d ago
CVE-2025-7771
ThrottleStop.sys Arbitrary Physical Memory R/W
6⭐
41d ago
CVE-2025-8045
Dirty Pagetable Exploit for CVE-2025-8045
7⭐
46d ago
SELinux-Permissive-Only-CVE-2025-21479
This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the…
4⭐
57d ago
CVE-2025-32432
Exploit, POC for CVE-2025-32432, CraftCMS2Shell
4⭐
59d ago
CVE-2025-64512
CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads
4⭐
61d ago
CVE-2025-8110-gogs-poc
PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink
7⭐
71d ago
CVE-2025-30065
This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It…
4⭐
76d ago
CVE-2025-69212-PoC
OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M…
3⭐
76d ago
CVE-2025-57819
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
4⭐
81d ago
CVE-2025-69212-PoC
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and…
5⭐
83d ago
CVE-2025-8110
PoC exploit for CVE-2025-8110
2024, 2023
Trending in 2024
Stars
Updated
Repository
Description
17⭐
31d ago
CVE-2024-56426
A PoC of the CVE-2024-56426 vulnerability.
4⭐
33d ago
CVE-2024-56426
CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F
3⭐
49d ago
CVE-2024-36104-PoC
PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path…
3⭐
87d ago
CVE-2024-36991
Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed.
Trending in 2023
Stars
Updated
Repository
Description
3⭐
52d ago
CVE-2023-52076-PoC
PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary…
6⭐
56d ago
CVE-2023-36003
PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender.
4⭐
71d ago
cve-2023-4911-exploit-optimized
Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing…
15⭐
73d ago
CVE-2023-32315-EXPLOIT
A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass
Data
Every file is plain JSON on the CDN. No key, no rate limit.
…
What CISA says is being exploited, that also has a PoC here, ranked by how
likely each is to be used next:
curl -s https://pocindex.io/kev.json -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
'[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
| sort_by(-.epss) | .[:10]'
Endpoint
Holds
CVE_list.json
Every CVE with a linked PoC, its description and its
poc,
nuclei,
msf,
edb,
vulhub and
collections links
cve_metadata.json
NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links
epss.json
Exploitation probability and percentile, for nearly every CVE indexed
nuclei.json
Template metadata for the CVEs covered by a runnable Nuclei check
kev.json
CISA known exploited, keyed by CVE id
repo_meta.json
Stars and last push date per PoC repository, keys lowercased
trending_poc.json
Trending repositories plus index totals
[
cves/2026/CVE-2026-68138.md](cves/20