
S2-072
Proof-of-concept exploit for the Apache Struts JSON plugin denial-of-service vulnerability (CVE-2026-73633), demonstrating CPU and memory exhaustion…
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Proof-of-concept exploit for the Apache Struts JSON plugin denial-of-service vulnerability (CVE-2026-73633), demonstrating CPU and memory exhaustion…
Proof-of-concept exploit for CVE-2026-64600 in RefluXFS, demonstrating the flaw and providing technical context for detection, patching, and further…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…

Python proof-of-concept for CVE-2026-53587, providing a focused exploit path to reproduce the vulnerability and support validation and defensive…

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

CVE-specific proof-of-concept written in Python for vulnerability validation and security testing.

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

Step-by-step demonstration of BlueKeep CVE-2019-0708 exploitation against Windows Remote Desktop Services, including RCE via crafted RDP packets and…

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…