
POC-CVE-2026-0300-exploit
Palo Alto - CVE-2026-0300 exploit

Palo Alto - CVE-2026-0300 exploit

Proof-of-Concept and technical analysis for CVE-2026-27654, a heap-based buffer overflow vulnerability in the NGINX HTTP WebDAV module, including…

CVE Reproduction: cve-2026-21509-office_security_bypass_reproduction

Proof-of-concept exploit for CVE-2026-9973, a V8 Turboshaft Load Elimination vulnerability enabling sandbox escape in Chromium. Demonstrates memory…

Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization

Integer overflow in FreeType software, which also affects Chrome

Reproducer for CVE-2026-43865 — Apache Camel camel-hazelcast default-configured instance unsafe Java deserialization (RCE)

Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Reproducer for CVE-2026-40473: Apache Camel camel-mina MinaConverter.toObjectInput unsafe deserialization (RCE over TCP/UDP)

Reproducer for CVE-2026-40048: Apache Camel camel-pqc FileBasedKeyLifecycleManager unsafe deserialization (RCE)

This is a Proof-of-Concept for the Blink CSS UAF vulnerability tracked as CVE-2026-6300.

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…


NGINX `ngx_http_dav_module` Heap Buffer Overflow via `size_t` Underflow (Remote DoS / Potential RCE)


POC for CVE-2025-29384

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…