
CVE-2026-71205-PoC
PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)
Tools for testing, exploiting, and securing web applications and APIs.

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

CVE-2026-74945 · Uninitialized heap disclosure via a crafted web font (sec-high)

CVE-2026-74943 · Use after free in Firefox RasterImage (sec-high)

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

CVE-2026-39154 · Stored XSS in CometChat JS SDK

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Confluence Unauthorized Administrator User Addition Exploitation Script

PoCs & write-ups for CVEs I reported (coordinated disclosure; published + patched only)

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)