
dockerevil
WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

Terraform and Docker resources for quickly spinning up a test of CVE-2021-44428

This repository contains BigFix Content that I created for identifying the AlmaLinux systems that require patching to remediate CVE-2026-31431

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

GitHub Actions workflow to test if the runner is vulnerable to CVE-2026-31431, confirming root privileges in a controlled environment.

we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in…

This is a script designed for deployment on ubuntu instances patching the CVE-2026-3888 exploit

Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271

Reproduces CVE-2026-21019 by manipulating node clock to force early Kubernetes CronJob execution; includes vulnerable YAML manifest and Python…

CVE-2024-10220 reveals a critical flaw in Kubernetes’ deprecated gitRepo volume type, allowing attackers to execute arbitrary commands via malicious…

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

Proof-of-concept exploit for CVE-2026-9999, demonstrating path traversal in serverless object storage events that overwrites function source code to…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

a Damn Vulnerable Serverless Application

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark