
POC-CVE-2026-63030-CVE-2026-60137-
Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept


An implementation of a vulnerable MCP server using mcp-go

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

POC for utilizing wikipedia API for Command and Control

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.


Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

OWASP Autonomous Penetration Testing Standard

Cobalt Strike HTTPS beaconing over Microsoft Graph API

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…