PoC Archive PoC Archive
security research · proof-of-concept archive

A reproducible archive of security research PoCs.

A curated archive of security research proof-of-concept exploits. Reproducible writeups across web, network, binary, crypto, cloud, hardware, and social-engineering categories.

Total PoCs

745

%!d(float64=37) added in the last 90 days

Patch status

300 / 445

unpatched / patched

CISA KEV

116

15.6% of the archive

Dominant vector

WEB

431 entries · 57.9%

Ransomware

33

known campaign use

LATEST ENTRIES view all 745 →
PoC titleSeverity
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web Unverified
CRITICAL 10
Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 / NSIDE-SA-2026-003 network Patched
CRITICAL 9.9
Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)
CVE-2026-8452 network Patched
CRITICAL 9.8
Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)
CVE-2026-2764 / MFSA 2026-13 binary Unverified
HIGH 8.8
Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361 binary Unverified
CRITICAL 9.8
Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111 binary Unverified
HIGH 7.8
nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Unverified
CRITICAL 9.8
PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f web Unverified
CRITICAL 9.8
Entering CISA KEV 37 in the last 90 days
3
03/26
8
04/26
8
05/26
17
06/26
13
07/26
3
08/26