CVE PoC Hub

Linked PoCs MITRE CVE pages Vendor / product filters Supports negative terms (e.g. -windows)

Recently updated Proof-of-Concepts

StarsUpdatedNameDescription
4037⭐ 10 hours ago copy-fail-CVE-2026-31431 Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
568⭐ 5 days ago cve_2026_31431 Exploit POC for CVE_2026_31431
318⭐ 11 hours ago CVE-2026-54121 Certighost POC
227⭐ 3 hours ago CVE-2026-43499-popsicle CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
209⭐ 18 days ago CVE-2026-41089 CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)
259⭐ 21 days ago CVE-2026-21858 n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)
206⭐ 1 day ago CVE-2026-24061 Exploitation of CVE-2026-24061
149⭐ 4 hours ago CVE-2026-43499 CVE-2026-43499 PoC
823⭐ 5 days ago CVE-2026-24061 CVE-2026-24061 exploit PoC
112⭐ 4 days ago CVE-2026-31431-Advanced-Exploit CVE-2026-31431 纯文件利用
115⭐ 5 days ago CVE-2026-41651
31⭐ 8 days ago cve-2026-31431 CVE-2026-31431: Copy Fail | A minimal exploit for Linux authencesn + AF_ALG + splice() page cache write.
61⭐ 23 days ago CVE-2026-45504 CVE-2026-45504 Microsoft Exchange File Read
15⭐ 4 days ago CVE-2026-43499-Poc-Analysis Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
283⭐ 10 hours ago cve-2026-41940-PoC A cPanel and WHM authentication bypassing tool
40⭐ 29 days ago CVE-2026-31431
187⭐ 6 days ago Copy-Fail-CVE-2026-31431-Kubernetes-PoC PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated on Alibaba Cloud ACK, Amazon EKS and Google GKE.
81⭐ 3 days ago CVE-2026-0073-Android-adbd-authentication-bypass-POC
102⭐ 35 days ago Copy-Fail-Exploit-CVE-2026-31431 Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.
70⭐ 2 days ago CVE-2026-34486 EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.