
CVE-2026-28134
JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution
Tools for weaponizing vulnerabilities to gain unauthorized access to systems or data.

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

Proof-of-concept exploit for Marimo pre-authentication RCE. Uses the unauthenticated /terminal/ws WebSocket endpoint to spawn a PTY and establish a…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Oracle OID LDAP Server Privileges Management Exploit

Proof-of-concept exploit code for CVE-2026-54121, adapted and edited for validating the vulnerability in affected environments.

halo cms plugin 1-request rce from a url, PoC + exploit chain

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案