Latest CVE PoCs
🧪 Collects CVE PoCs and backs them up to the Internet Archive when they are unavailable on GitHub.
CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security testing & research only.
Search 82,000+ public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit and Vulhub.
CVE/poc推送|403的问题太难啦┭┮﹏┭┮|将就着用吧^待到来年春天再优化
Search for Proof of Concept exploits by CVE ID.
VulnWatchdog 是一个自动化的漏洞监控和分析工具。它可以监控 GitHub 上的 CVE 相关仓库,获取漏洞信息和 POC 代码,并使用 GPT 进行智能分析,生成详细的分析报告。
Critical CVE research, vulnerability analysis, PoC references and security intelligence by StemShop.
CVE POC repo 자동 수집기
Aggregates multiple data sources related to CVE exploits/PoC.
A structured archive of Proof-of-Concept security research, organized by category with metadata, reproduction steps, and references.
Automatically push newly disclosed POC information.
Versioned PoC dataset collected from GitHub for CVE research and threat intelligence.
VulnWatchdog 是一个自动化的漏洞监控和分析工具。它可以监控 GitHub 上的 CVE 相关仓库,获取漏洞信息和 POC 代码,并使用 GPT 进行智能分析,生成详细的分析报告。
JPEG XL auto-decodes in the iOS Messages preview path — delivery-surface finding for CVE-2026-28956 (AppleJPEGXL), with patch-diff attribution (libjxl 0.10.4->0.10.5) and an honest reliability check on the public PoC.
🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
Scan Node.js projects for vulnerabilities using OSV.dev data. Use this tool as a command-line interface or a gated step in your CI pipeline.
Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.
Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.
🏆 Discover top ML/NLP research by exploring Best Paper winners from major venues (2022-2026) to enhance your understanding of high-impact work.
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
🧠 Automatically collects and updates public Proof-of-Concept (PoC) exploits from poc-in-github.motikan2010.net
Root cause + macOS reachability PoC for CVE-2026-64747 (AppleAVE2 kext buffer overflow, fixed 26.6 / 905.40.1). Fully reversed AppleAVE2UserClient wire protocol, mode-5 LRB overflow math, IOKit PoC driving the configure path.
Root cause + PoC for CVE-2026-64705 (macOS HFS xattr kernel heap overflow, fixed 14.8.7). Weaponized HFS+ image: unbounded bcopy loop -> kernel heap overflow -> panic on pre-fix systems; validator rejection on patched. Kext diff, mechanism, rebuild recipe.
Root cause analysis + working R/W exploit for CVE-2026-78938 (V8 TurboFan CheckMaps instance-migration type confusion, Chrome 152, exploited in the wild). Crash PoC + addrof/fakeobj/arbitrary R/W over the compressed heap.
Live CVE PoC (Proof-of-Concepts) Aggregator with Smart Search & Threat Intelligence
Gather and update all available and newest CVEs with their POC.
keep togheter all the forked repo's regarding CVE or PoC
Dockerized Spring4Shell (CVE-2022-22965) PoC application and exploit
Lab Docker dựng CMS Made Simple 2.2.5 (Wawa) và tái hiện CVE-2018-1000094 (authenticated RCE). Bao gồm hướng dẫn setup, PoC, và tài liệu kiểm thử.
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
Proof of Concept exploit for CVE-2025-8088 - WinRAR path traversal vulnerability affecting versions ≤7.12. Educational tool demonstrating ADS-based file extraction bypass. ⚠️ Research purposes only.