
Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.
Every file is plain JSON on the CDN. No key, no rate limit.
# everything the index knows about one CVE
curl -s https://pocindex.io/CVE_list.json \
| jq '.[] | select(.cve == "CVE-2021-44228") | {cve, poc: (.poc | length), nuclei, msf, edb, vulhub, collections}'
# every published CVSS assessment plus vetted advisory links
curl -s https://pocindex.io/cve_metadata.json | jq '."CVE-2021-44228"'
# likelihood of exploitation in the next 30 days
curl -s https://pocindex.io/epss.json | jq '."CVE-2021-44228"'
# stars and last push for one PoC repository; repository keys are lowercased
curl -s https://pocindex.io/repo_meta.json | jq '."sfewer-r7/cve-2026-55040"'
What CISA says is being exploited, that also has a PoC here, ranked by how likely each is to be used next:
curl -s https://pocindex.io/kev.json -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
'[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
| sort_by(-.epss) | .[:10]'
CVSS rows are [version, score, severity, vector, source, assessment type].
Advisory rows are [URL, NVD reference tags].
Missing PoC, wrong link, dead repository: open an issue with the CVE id and the repository URL.
| Stars | Updated | Repository | Description |
|---|
| 0⭐ | 14h ago | CVE-2025-39401 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows… |
| 0⭐ | 1d ago | CVE-2025-69080 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')… |
| 0⭐ | 1d ago | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and… | |
| 10⭐ | 2d ago | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of… | |
| 2⭐ | 2d ago | CVE-2026-78904-Digital-Dinar-Drain | CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central… |
| 0⭐ | 2d ago | CVE-2025-6440 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services… |
| 2⭐ | 3d ago | CVE-2026-19745 | Learn how I found my first two CVEs by pure accident. |
| 2⭐ | 3d ago | Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078 | |
| 0⭐ | 3d ago | cve-2025-29927 | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior… |
| 2⭐ | 5d ago | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A… |
| Stars | Updated | Repository | Description |
|---|
| 10⭐ | 2d ago | givewp-cve-2026-82222-rce-lab | Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix. |
| 18⭐ | 5d ago | Metabase SQLi | |
| 4⭐ | 5d ago | CVE-2026-19478 | GitLab Code injection |
| 3⭐ | 5d ago | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion… | |
| 4⭐ | 6d ago | Zimbra SNMP Notification OS Command Injection - Unauthenticated RCE via SMTP exploit (Poc) | |
| 81⭐ | 6d ago | CVE-2026-75604-poc | CVE-2026-75604 Next.js Windows RCE poc |
| 5⭐ | 7d ago | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional… | |
| 3⭐ | 7d ago | CVE-2026-32475-PoC | PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python. |
| 13⭐ | 7d ago | Keycloak_CVE-2026-18963_PoC | This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...). |
| 19⭐ | 8d ago | CVE-2026-18963-keycloak | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine… |
| 4⭐ | 8d ago | CVE-2026-20079 | Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center. |
| 4⭐ | 10d ago | Apple MacOS Screen Sharing Arbitrary File read/write -> RCE | |
| 160⭐ | 10d ago | CVE-2026-62911 | POC pre-auth RCE on Exchange |
| 4⭐ | 11d ago | Read-only PoC for CVE-2026-65400 - macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file… | |
| 6⭐ | 11d ago | CVE-2026-34910/34909 - UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW) | |
| 53⭐ | 11d ago | CVE-2026-64638-PoC-XSS2Shell- | XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain - PoC exploit + defensive audit tool + nuclei… |
| 37⭐ | 12d ago | CVE-2026-18963-Exploit | Exploit for KeyCloak CVE-2026-18963 |
| 432⭐ | 12d ago | CVE-2026-9830 | CVE-2026-9830 Proof of Concept |
| 531⭐ | 12d ago | A cPanel and WHM authentication bypassing tool | |
| 824⭐ | 12d ago | CVE-2026-24061 exploit PoC |
| Stars | Updated | Repository | Description |
|---|
| 6⭐ | 5d ago | Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of… | |
| 4⭐ | 13d ago | Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables… | |
| 20⭐ | 22d ago | CVE-2025-7771 | ThrottleStop.sys Arbitrary Physical Memory R/W |
| 6⭐ | 26d ago | CVE-2025-8045 | Dirty Pagetable Exploit for CVE-2025-8045 |
| 6⭐ | 30d ago | This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the… | |
| 4⭐ | 42d ago | Exploit, POC for CVE-2025-32432, CraftCMS2Shell | |
| 4⭐ | 44d ago | CVE-2025-64512 | CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads |
| 5⭐ | 46d ago | PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink | |
| 7⭐ | 55d ago | CVE-2025-30065 | This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It… |
| 4⭐ | 61d ago | CVE-2025-69212-PoC | OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M… |
| 3⭐ | 61d ago | CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE) | |
| 4⭐ | 66d ago | CVE-2025-69212-PoC | OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and… |
| 5⭐ | 68d ago | PoC exploit for CVE-2025-8110 | |
| 14⭐ | 81d ago | vulnerable-nextjs-14-CVE-2025-29927 | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior… |
| 14⭐ | 87d ago | FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable… | |
| 7⭐ | 87d ago | CVE-2025-57819 -> rce |
| Stars | Updated | Repository | Description |
|---|
| 16⭐ | 16d ago | CVE-2024-56426 | A PoC of the CVE-2024-56426 vulnerability. |
| 3⭐ | 17d ago | CVE-2024-56426 | CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F |
| 3⭐ | 34d ago | CVE-2024-36104-PoC | PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path… |
| 3⭐ | 72d ago | CVE-2024-36991 | Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed. |
| 7⭐ | 81d ago | CVE-2024-27983-nodejs-http2 | CVE-2024-27983 this repository builds up a vulnerable HTTP2 Node.js server (server-nossl.js) based on… |
| 4⭐ | 87d ago | CVE-2024-1065 | Page Cache Exploit for CVE-2024-1065 |
| Stars | Updated | Repository | Description |
|---|---|---|---|
| 3⭐ | 36d ago | CVE-2023-52076-PoC | PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary… |
| 5⭐ | 41d ago | CVE-2023-36003 | PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender. |
| 3⭐ | 56d ago | Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing… | |
| 15⭐ | 58d ago | A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass | |
| 6⭐ | 74d ago | CVE-2023-6019 | PoC exploit for CVE-2023-6019 - Remote Code Execution via unauthenticated Ray Dashboard Jobs API. |
| Stars | Updated | Repository | Description |
|---|---|---|---|
| 6⭐ | 76d ago | NimbusPWN-CVE-2022-29799-29800 | NimbusPwn (CVE-2022-29799/29800) local privilege escalation PoC in C. |
| Endpoint | Holds |
|---|
CVE_list.json | Every CVE with a linked PoC, its description and its poc, nuclei, msf, edb, vulhub and collections links |
cve_metadata.json | NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links |
epss.json | Exploitation probability and percentile, for nearly every CVE indexed |
nuclei.json | Template metadata for the CVEs covered by a runnable Nuclei check |
kev.json | CISA known exploited, keyed by CVE id |
repo_meta.json | Stars and last push date per PoC repository, keys lowercased |
trending_poc.json | Trending repositories plus index totals |
cves/2026/CVE-2026-68138.md | Markdown copy of one CVE, one directory per year |
| Source | What it contributes |
|---|
| GitHub | Repositories naming a CVE, checked for code before they are linked |
| PoC-in-GitHub | Historical repository candidates, passed through the same code and intent checks |
| Nuclei | Runnable templates that exercise the vulnerability |
| ExploitDB | Archived exploits, mapped by their own CVE column |
| Metasploit | Modules, best ranked first |
| Vulhub | Runnable vulnerable environments and reproduction steps |
| afrog, Vulnerability, 0day, xray | CVE-specific templates, code and reproduction guides inside multi-CVE repositories |
| EPSS | Daily exploitation probability from FIRST |
| CISA KEV | What is being exploited in the wild |
| NVD | CVSS assessments and tagged vendor, third-party, patch and mitigation references |
| CVE Program | The CVE record, publication state and CNA references |
| Job | Cadence | Picks up |
|---|
| Trending sweep | hourly | Front-page repositories and prior-hour candidates added to the searchable index |
| CVE sync | daily | New CVEs, CNA references and recently pushed GitHub repositories for every CVE year |
| Metadata sync | daily plus weekly full pass | CVSS, advisories, rejected records and current CISA KEV status |
| Nuclei sync | daily | New templates and rating changes |
| Exploit archives | daily | ExploitDB, Metasploit and Vulhub mappings |
| Historical GitHub sync | weekly | Older PoC repositories missed by the recent-push window |
| Path collection sync | weekly | CVE-specific artifacts inside curated multi-CVE repositories |
| Link audit | weekly | Repositories that went dead, dropped from the index |