security research · proof-of-concept archive
A reproducible archive of security research PoCs.
A curated archive of security research proof-of-concept exploits. Reproducible writeups across web, network, binary, crypto, cloud, hardware, and social-engineering categories.
Total PoCs
773
%!d(float64=13) added in the last 90 days
Patch status
322 / 451
unpatched / patched
CISA KEV
119
15.4% of the archive
Dominant vector
WEB
437 entries · 56.5%
Ransomware
33
known campaign use
LATEST ENTRIES
view all 773 →
| PoC title | CVE | Category | Severity | Patch |
|---|---|---|---|---|
| PaperCut MF/NG Auth Bypass + RCE Chain (CVE-2026-81578 / CVE-2026-82078) CVE-2026-81578, CVE-2026-82078
web
Unverified | CVE-2026-81578, CVE-2026-82078 | web | CRITICAL 9.8 | Unverified |
| WordPress Divi Ajax Filter LFI (CVE-2026-11613) CVE-2026-11613
web
Unverified | CVE-2026-11613 | web | CRITICAL 9.8 | Unverified |
| Linux Bridge Fast-Leave Port Deletion UAF LPE (CVE-2026-74480) CVE-2026-74480
binary
Unverified | CVE-2026-74480 | binary | CRITICAL 9.8 | Unverified |
| Linux io_uring Poll Signed Comparison LPE (CVE-2026-52933) CVE-2026-52933
binary
Unverified | CVE-2026-52933 | binary | HIGH 7.8 | Unverified |
| Linux IPv6 fib6 Rule Suppression UAF LPE (CVE-2026-74581) CVE-2026-74581
binary
Unverified | CVE-2026-74581 | binary | HIGH 7.8 | Unverified |
| Linux IPVS One-Packet Flag Propagation UAF LPE (CVE-2026-80714) CVE-2026-80714
binary
Unverified | CVE-2026-80714 | binary | CRITICAL 9.8 | Unverified |
| Linux Netfilter nf_queue Bridge Device UAF LPE (CVE-2026-72255) CVE-2026-72255
binary
Unverified | CVE-2026-72255 | binary | HIGH 7.8 | Unverified |
| Linux Open vSwitch Tunnel Netdev UAF LPE (CVE-2026-31678) CVE-2026-31678
binary
Unverified | CVE-2026-31678 | binary | HIGH 7.8 | Unverified |
Entering CISA KEV
13 in the last 90 days
8
05/26
17
06/26
13
07/26
6
08/26
0
09/26
0
10/26
Highest exploit probability
all →
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD)
100%
CVE-2024-23897
100%
CVE-2024-3400
100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706
100%
CVE-2025-3248
100%
CVE-2022-40684
100%
CVE-2023-22527
100%
CVE-2025-22457
100%
CVE-2025-0282
100%
CVE-2025-5777
100%
FIRST EPSS — probability of exploitation within 30 days. Red = also in CISA KEV.
Target technologies
WordPress
103 ·1
Linux
51 ·2
Windows
47 ·13
Apache
23 ·1
Next.js
18 ·2
Node.js
15
Git
15 ·2
Microsoft
10 ·3
Veno
10
Joomla
9 ·5
Red = confirmed exploited in the wild.