
CVE-2019-1253
AppXSvc Arbitrary File Security Descriptor Overwrite EoP

AppXSvc Arbitrary File Security Descriptor Overwrite EoP

Reproducer for CVE-2026-46590: Apache Camel camel-pqc key-lifecycle unsafe deserialization (FileBasedKeyLifecycleManager legacy .key migration via…

PoC for CVE-2018-20343

Reproducer for CVE-2026-27172: Apache Camel camel-consul ConsulRegistry Java deserialization (RCE)

Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Reproducer for CVE-2026-43865 — Apache Camel camel-hazelcast default-configured instance unsafe Java deserialization (RCE)

Reproducer for CVE-2026-40858 — Apache Camel camel-infinispan remote aggregation repository unsafe deserialization (RCE)


Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)

PoC demonstrating the use of cve-2020-1034 for privilege escalation


Real world and CTFs exploiting web/binary POCs.

Report and exploit of CVE-2023-36427

#INFILTRATE20 raptor's party pack.

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)