
A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.
The definitive community-curated index of verified Proof-of-Concept (PoC) exploits, technical root-cause analyses, and vulnerability research for CVEs disclosed in 2026.
| 🏢 Category | Primary Target Technologies / Vendors |
|---|---|
| 🌐 Web & CMS | WordPress Core, WooCommerce, Elementor, Apache HTTP, Nginx, Node.js |
| 🏢 Enterprise & Auth | Microsoft Exchange, SharePoint, Active Directory, Keycloak, SAP NetWeaver, Oracle WebLogic |
| 🛡️ Network & Firewalls | Palo Alto PAN-OS, Fortinet FortiOS, Cisco IOS XE / ISE, F5 BIG-IP, SonicWall SMA, Check Point |
| ☁️ Cloud & DevOps | Kubernetes, Docker & runc, HashiCorp Vault/Nomad, GitLab, Jenkins, Grafana |
| 🐧 Kernels & Systems | Linux Kernel (eBPF/netfilter/io_uring), Windows Kernel (CLFS/Win32k), VMware ESXi, Android, Apple iOS |
This repository indexes, tracks, and documents Proof-of-Concept exploits for all 2026 CVEs with verified upstream researcher attribution, official vendor advisories, and standardized non-destructive verification skeletons.
poc.py --verify-only) for lab security audits.| Total CVEs | 🔴 Critical | 🟠 High | 🟡 Medium+ | PoCs Available | Last Updated |
|---|---|---|---|---|---|
| 2356 | 1188 | 1111 | 57 | 2356 | 2026-09-30 |
| CVE ID | CVSS | Product | Vuln Class | Day | Added |
|---|---|---|---|---|---|
| CVE-2026-102578 | 🟠 8.8 | Moodle LMS | SQL Injection in Question... | — | 2026-09-30 |
| CVE-2026-102456 | 🟠 8.8 | DigiWin EasyFlow | SQL Injection in Form Routing | — | 2026-09-30 |
| CVE-2026-102580 | 🟠 8.5 | Moodle LMS | Arbitrary Class... | — | 2026-09-30 |
| CVE-2026-102588 | 🟠 7.5 | Moodle LMS | Cross-Site Request Forgery... | — | 2026-09-30 |
| CVE-2026-102583 | 🟠 7.5 | Moodle LMS | Direct Request /... | — | 2026-09-30 |
| CVE-2026-102459 | 🟠 7.5 | DigiWin EasyFlow | Reflected Cross-Site... | — | 2026-09-30 |
| CVE-2026-86102 | 🔴 9.8 | WatchGuard Access | OS Command Injection in... | — | 2026-09-29 |
| CVE-2026-85102 | 🔴 9.8 | Check Point | Improper Certificate... | — | 2026-09-29 |
| CVE-2026-63713 | 🔴 9.8 | Toptech TopHAT | OS Command Injection in... | — | 2026-09-29 |
| CVE-2026-72507 | 🔴 9.6 | Toptech TMS7 | Insecure Deserialization... | — | 2026-09-29 |