security research · proof-of-concept archive
A reproducible archive of security research PoCs.
A curated archive of security research proof-of-concept exploits. Reproducible writeups across web, network, binary, crypto, cloud, hardware, and social-engineering categories.
Total PoCs
745
%!d(float64=37) added in the last 90 days
Patch status
300 / 445
unpatched / patched
CISA KEV
116
15.6% of the archive
Dominant vector
WEB
431 entries · 57.9%
Ransomware
33
known campaign use
LATEST ENTRIES
view all 745 →
| PoC title | CVE | Category | Severity | Patch |
|---|---|---|---|---|
| Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267) CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7
web
Unverified | CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 | web | CRITICAL 10 | Unverified |
| Cisco IMC Argument Injection to Root RCE (CVE-2026-20200) CVE-2026-20200 / NSIDE-SA-2026-003
network
Patched | CVE-2026-20200 / NSIDE-SA-2026-003 | network | CRITICAL 9.9 | Patched |
| Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) CVE-2026-8452
network
Patched | CVE-2026-8452 | network | CRITICAL 9.8 | Patched |
| Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764) CVE-2026-2764 / MFSA 2026-13
binary
Unverified | CVE-2026-2764 / MFSA 2026-13 | binary | HIGH 8.8 | Unverified |
| Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361) CVE-2026-53361
binary
Unverified | CVE-2026-53361 | binary | CRITICAL 9.8 | Unverified |
| Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111) CVE-2026-23111
binary
Unverified | CVE-2026-23111 | binary | HIGH 7.8 | Unverified |
| nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533) CVE-2026-42533
web
Unverified | CVE-2026-42533 | web | CRITICAL 9.8 | Unverified |
| PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544) CVE-2026-17544 / GHSA-x692-q9x7-8c3f
web
Unverified | CVE-2026-17544 / GHSA-x692-q9x7-8c3f | web | CRITICAL 9.8 | Unverified |
Entering CISA KEV
37 in the last 90 days
3
03/26
8
04/26
8
05/26
17
06/26
13
07/26
3
08/26
Highest exploit probability
filter →
CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD)
100%
CVE-2024-23897
100%
CVE-2024-3400
100%
CVE-2025-3248
100%
CVE-2025-22457
100%
CVE-2022-40684
100%
CVE-2023-22527
100%
CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706
100%
CVE-2025-0282
100%
CVE-2025-5777
100%
FIRST EPSS — probability of exploitation within 30 days. Red = also in CISA KEV.
Target technologies
WordPress
101 ·1
Windows
47 ·12
Linux
34 ·2
Apache
23 ·1
Next.js
17 ·2
Git
15 ·2
Node.js
14
Microsoft
10 ·3
Veno
10
Joomla
9 ·5
Red = confirmed exploited in the wild.