A consolidated archive of public proof-of-concept exploits and vulnerability research writeups, covering over 20 different software targets with verified integrity of tracked files.

Stars

69

7-day growth

No data

Forks

124

Open issues

0

License

No data

Last updated

2026-06-29

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

This repository serves as a rare, centralized collection of 0-day and near-0-day proof-of-concept exploits across a wide range of popular software, with a systematic consolidation check that guarantees the tracked files are byte-for-byte identical to the original standalone repositories.

Who it is for

  • Security researchers studying exploit techniques
  • Penetration testers and red teamers needing real-world PoCs
  • Software developers auditing their own products for similar vulnerabilities
  • Bug bounty hunters looking for inspiration or reference material

Use cases

  • Analyzing exploit patterns in widely-used software like 7-Zip, Firefox, Docker, and Ghidra
  • Testing security controls (e.g., EDR, sandboxing) against known PoCs
  • Verifying that patches or mitigations break the demonstrated attack chains
  • Educational use in offensive security training or capture-the-flag challenges

Strengths

  • Consolidation check verified 12 former standalone repos with 96 tracked entries and zero mismatches, ensuring file integrity
  • Covers a diverse set of targets: archive tools, remote desktop, libraries, VMs, browsers, debuggers, web apps, and more
  • Both preserved standalone repos (with original READMEs) and new direct entries are tracked under a single repository, making navigation easy
  • Author explicitly welcomes collaboration and requests for new targets via GitHub issues

Considerations

  • Repository metadata (stars, issues, releases, Git history) from original standalone repos is not preserved here
  • PoCs are provided as-is with no guarantee of continued functionality after software updates or patching
  • Some entries have future dates (e.g., June 2026), which may cause confusion about vulnerability disclosure timelines

README quick start

If you wish to collaborate/discuss with me, contact me on discord @ashdfrkl

Sharing this repo keeps me motivated to continue dropping 0-days for you all.

Open an issue if you have a specific request for software you want me to take a look at.

Exploitarium

A consolidated archive of my public proof-of-concept and vulnerability research writeups.

Most folders contain one of my former standalone PoC repos, preserved with its original README and tracked files. New research entries are added directly here as self-contained folders.

Contents

FolderSourceTracked entries
7zip-rar5-motw-chain-pocbd9533f532c1e4ee6af783b9bb49d1133c600e2c3
anydesk-printer-com-impersonation-poc7491303301093b2d40bee9dadf6b38f757ce78e04
c-ares-tcp-uaf-calc-pocdirect entry, June 24, 20267
docker-cp-copyout-destination-escaped1367b1381736d7f961ac808ce88d4e24a633adc5
firefox-smartwindow-private-url-exfil-pocdirect entry, June 24, 20263
floci-apigateway-vtl-rce-pocdirect entry, June 23, 20263
flowise-mcp-env-case-bypass-poced9fab0086674f1b16467990b33bb9299e93429e3
ffmpeg-rasc-dlta-calc-pocdirect entry, June 26, 20267
ghidra-12.1.2-rce-ace-calc-poc52dee6362990c03c0d753d074c85428824d463689
gitea-act-runner-container-options-pocf06d78fb111732f3e7737f4c07e77ef94c4b64bf4
imagemagick-gs-delegate-hijack-poc8140e8ee0ed78beaf5e8303a795b70b138f5891b5
libssh2-cve-2026-55200-pocdirect entry, June 23, 20263
libssh2-publickey-list-calc-pocdirect entry, June 25, 202610
lunar-modrinth-chain-pocffd02120708b6503f11585858ce3724872f3b7a76
mybb-limited-acp-to-admin1610e0373943c2f6562a99f917d3a3d1fdd9056d5
nghttp2-nghttpx-upgrade-queue-poison-pocdirect entry, June 26, 20263
nmap-ipv6-extlen-wrap-pocdirect entry, June 23, 20264
objdump-dlx-calc-poc7df01e4e20c7375a89e8ccf760526c52eb6ad58241
openvpn-connect-echo-script-ace-pocd2f904d9272d4388c9862131d40e32e072e85e388
php857-streambucket-soap-rce-rpocdirect entry, June 26, 20266
rustdesk-session-permission-pocsdirect entry, June 25, 202617
systeminformer-phsvc-trusted-host-lpe-pocdirect entry, June 24, 20263
vlc-vp9-reschange-crash-poc`fae

Related repositories

Similar projects matched by category, topics, and programming language.

lopopolo
Featured
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI & Machine LearningAI Agents
2,390
slvDev
Featured
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI & Machine LearningLarge Language Models
1,960
littledivy
Featured
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI & Machine Learning
1,482