0xMarcio/pocindex

Pythonpocindex.io

Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.

cisa-kevcvecve-poccvssepssexploitexploit-databaseexploitdbinfosecmetasploitnucleipentesting
Star Growth
Stars
1.4k
Forks
169
Weekly Growth
Issues
0
5001k
Jul 2024Mar 2025Dec 2025Sep 2026
ArtifactsPyPI
README

PoC Index

last sync CI CVEs with PoCs known exploited stars

Search PoC Index

Just landed

Stars Updated Repository Description
0⭐ 15h ago KEV CVE-2025-31324 SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing…
0⭐ 18h ago KEV CVE-2025-57819 CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)
0⭐ 1d ago CVE-2026-49777 Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for…
0⭐ 1d ago CVE-2025-24799 GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection…
0⭐ 1d ago KEV POC-CVE-2025-68613 n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4,…
0⭐ 1d ago CVE-2025-4255---Buffer-Overflow Exploit Framework for CVE-2025-4255
2⭐ 1d ago CVE-2026-58138 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that…
2⭐ 2d ago KEV cve-2026-85046-poc Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary…
0⭐ 2d ago CVE-2025-29927-PoC Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior…
1⭐ 2d ago CVE-2026-32475 CVE-2026-32475 PoC : Elementor Pro Unauthenticated Arbitrary File Upload to RCE
Stars Updated Repository Description
4⭐ 1d ago KEV CVE-2026-41091-PoC-Exploit CVE-2026-41091 RedSun / Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM 🔥 via…
10⭐ 2d ago xiaomi15-dada-cve-2026-64560 Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
6⭐ 2d ago cve-2026-32475-elementor-pro-lab A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via…
5⭐ 2d ago KEV CVE-2026-15409-15410-Framework CVE-2026-15409/15410 SonicWall SMA1000 multi-exploit Framework 🔥 SSRF→Erlang RPC→RCE→root privesc. Features:…
3⭐ 4d ago CVE-2026-62735 Windows HTTP.sys integer overflow -> nonpaged pool overflow LPE PoC (CVE-2026-62735): crash + full SYSTEM…
10⭐ 4d ago CVE-2026-19490 NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause…
3⭐ 7d ago CVE-2026-78904-Digital-Dinar-Drain CBDC Infrastructure Vulnerability Research. CVE-2026-78904: Infinite mint and redemption bypass in central…
16⭐ 8d ago givewp-cve-2026-82222-rce-lab Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
3⭐ 9d ago KEV PaperCut-CVE-2026-81578-82078 Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
26⭐ 11d ago CVE-2026-62735 CVE 1-day in http.sys
21⭐ 11d ago KEV CVE-2026-72898 Metabase SQLi
4⭐ 11d ago CVE-2026-19478 GitLab Code injection
3⭐ 11d ago KEV CVE-2026-21962 Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion…
4⭐ 12d ago KEV CVE-2026-73570 Zimbra SNMP Notification OS Command Injection - Unauthenticated RCE via SMTP exploit (Poc)
88⭐ 12d ago CVE-2026-75604-poc CVE-2026-75604 Next.js Windows RCE poc
5⭐ 12d ago KEV CVE-2026-73570 A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional…
3⭐ 13d ago CVE-2026-32475-PoC PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.
13⭐ 13d ago Keycloak_CVE-2026-18963_PoC This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).
19⭐ 13d ago CVE-2026-18963-keycloak A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine…
4⭐ 13d ago CVE-2026-20079 Python proof of concept for CVE-2026-20079 affecting Cisco Secure Firewall Management Center.
Stars Updated Repository Description
6⭐ 11d ago KEV vivo_iqoo_neo_9_root_research_on_CVE-2025-21479 Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of…
4⭐ 18d ago KEV cve-2025-21479_iqooneo8 Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables…
20⭐ 27d ago CVE-2025-7771 ThrottleStop.sys Arbitrary Physical Memory R/W
6⭐ 32d ago CVE-2025-8045 Dirty Pagetable Exploit for CVE-2025-8045
7⭐ 36d ago KEV SELinux-Permissive-Only-CVE-2025-21479 This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the…
4⭐ 47d ago KEV CVE-2025-32432 Exploit, POC for CVE-2025-32432, CraftCMS2Shell
4⭐ 50d ago CVE-2025-64512 CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads
5⭐ 52d ago KEV CVE-2025-8110-gogs-poc PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink
7⭐ 61d ago CVE-2025-30065 This PoC targets CVE-2025-30065, an RCE vulnerability in Apache Parquet via Avro schema deserialization. It…
4⭐ 66d ago CVE-2025-69212-PoC OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M…
3⭐ 66d ago KEV CVE-2025-57819 CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
4⭐ 71d ago CVE-2025-69212-PoC OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and…
5⭐ 73d ago KEV CVE-2025-8110 PoC exploit for CVE-2025-8110
14⭐ 87d ago vulnerable-nextjs-14-CVE-2025-29927 Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior…
2024, 2023, 2022
Stars Updated Repository Description
16⭐ 21d ago CVE-2024-56426 A PoC of the CVE-2024-56426 vulnerability.
3⭐ 23d ago CVE-2024-56426 CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F
3⭐ 39d ago CVE-2024-36104-PoC PoC for CVE-2024-36104 - unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path…
3⭐ 78d ago CVE-2024-36991 Exploit for CVE-2024-36991 , written by me, enumerates a handfull of things, not all, cause not needed.
7⭐ 87d ago CVE-2024-27983-nodejs-http2 CVE-2024-27983 this repository builds up a vulnerable HTTP2 Node.js server (server-nossl.js) based on…
Stars Updated Repository Description
3⭐ 42d ago CVE-2023-52076-PoC PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary…
5⭐ 46d ago CVE-2023-36003 PoC for CVE-2023-36003: Windows Exploit Security Feature Bypass Vulnerability in Windows Defender.
3⭐ 61d ago KEV cve-2023-4911-exploit-optimized Pure C exploit for CVE-2023-4911 (Looney Tunables) - x86_64 & aarch64 implementations. Multi-processing…
15⭐ 63d ago KEV CVE-2023-32315-EXPLOIT A PoC exploit for CVE-2023-32315 - Openfire Authentication Bypass
6⭐ 79d ago CVE-2023-6019 PoC exploit for CVE-2023-6019 - Remote Code Execution via unauthenticated Ray Dashboard Jobs API.
Stars Updated Repository Description
6⭐ 81d ago NimbusPWN-CVE-2022-29799-29800 NimbusPwn (CVE-2022-29799/29800) local privilege escalation PoC in C.

Data

Every file is plain JSON on the CDN. No key, no rate limit.

# everything the index knows about one CVE
curl -s https://pocindex.io/CVE_list.json \
  | jq '.[] | select(.cve == "CVE-2021-44228") | {cve, poc: (.poc | length), nuclei, msf, edb, vulhub, collections}'

# every published CVSS assessment plus vetted advisory links
curl -s https://pocindex.io/cve_metadata.json | jq '."CVE-2021-44228"'

# likelihood of exploitation in the next 30 days
curl -s https://pocindex.io/epss.json | jq '."CVE-2021-44228"'

# stars and last push for one PoC repository; repository keys are lowercased
curl -s https://pocindex.io/repo_meta.json | jq '."sfewer-r7/cve-2026-55040"'

What CISA says is being exploited, that also has a PoC here, ranked by how likely each is to be used next:

curl -s https://pocindex.io/kev.json  -o kev.json
curl -s https://pocindex.io/epss.json -o epss.json
jq -n --slurpfile kev kev.json --slurpfile epss epss.json \
  '[$kev[0] | keys[] | select($epss[0][.]) | {cve: ., epss: $epss[0][.][0]}]
   | sort_by(-.epss) | .[:10]'
Endpoint Holds
CVE_list.json Every CVE with a linked PoC, its description and its poc, nuclei, msf, edb, vulhub and collections links
cve_metadata.json NVD CVSS v2.0, v3.0, v3.1 and v4.0 assessments with vectors and vetted advisory links
epss.json Exploitation probability and percentile, for nearly every CVE indexed
nuclei.json Template metadata for the CVEs covered by a runnable Nuclei check
kev.json CISA known exploited, keyed by CVE id
repo_meta.json Stars and last push date per PoC repository, keys lowercased
trending_poc.json Trending repositories plus index totals
cves/2026/CVE-2026-68138.md Markdown copy of one CVE, one directory per year

CVSS rows are [version, score, severity, vector, source, assessment type]. Advisory rows are [URL, NVD reference tags].

Sources

Source What it contributes
GitHub Repositories naming a CVE, checked for code before they are linked
PoC-in-GitHub Historical repository candidates, passed through the same code and intent checks
Nuclei Runnable templates that exercise the vulnerability
ExploitDB Archived exploits, mapped by their own CVE column
Metasploit Modules, best ranked first
Vulhub Runnable vulnerable environments and reproduction steps
afrog, Vulnerability, 0day, xray CVE-specific templates, code and reproduction guides inside multi-CVE repositories
EPSS Daily exploitation probability from FIRST
CISA KEV What is being exploited in the wild
NVD CVSS assessments and tagged vendor, third-party, patch and mitigation references
CVE Program The CVE record, publication state and CNA references

Build

Job Cadence Picks up
Trending sweep hourly Front-page repositories and prior-hour candidates added to the searchable index
CVE sync daily New CVEs, CNA references and recently pushed GitHub repositories for every CVE year
Metadata sync daily plus weekly full pass CVSS, advisories, rejected records and current CISA KEV status
Nuclei sync daily New templates and rating changes
Exploit archives daily ExploitDB, Metasploit and Vulhub mappings
Historical GitHub sync weekly Older PoC repositories missed by the recent-push window
Path collection sync weekly CVE-specific artifacts inside curated multi-CVE repositories
Link audit weekly Repositories that went dead, dropped from the index

Contributing

Missing PoC, wrong link, dead repository: open an issue with the CVE id and the repository URL.