
CVE-2026-68138
Track patch status for CVE-2026-68138, a Linux kernel net/sched qdisc rate-table use-after-free, with affected/fixed versions, upstream commits, and…
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Track patch status for CVE-2026-68138, a Linux kernel net/sched qdisc rate-table use-after-free, with affected/fixed versions, upstream commits, and…
PowerShell proof-of-concept that triggers CVE-2026-62737, an arbitrary kernel call in ExecutionContext.sys, causing a controlled kernel crash on…

Confluence Unauthorized Administrator User Addition Exploitation Script

iPad 8 iPadOS 26.3 AVE toolchain research (CVE-2026-64747 class)

A security research archive documenting vulnerabilities, technical analysis, and PoC demonstrations.

Windows Defender patch bypass PoC for CVE-2026-50656 (RoguePlanet), demonstrating exploitability on Windows 11 25H2 and Server 2025 despite…

PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only)

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Deep-dive analysis of Windows CLFS type confusion (CVE-2022-24481) with root-cause explanation, exploitation flow, kernel gadget details, and working…

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.