
CVE-2022-3294
Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

PoC de CVE-2026-54420: explotacion via symlink en el plugin LiteSpeed de cPanel/WHM.

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

Exploit for CVE-2019-5737, a Docker runc container escape vulnerability, with build and run instructions for Linux and Windows.

2025年8月20日に公開されたDockerDesktopの脆弱性(対策済み)を実証する

Proof-of-concept exploit for CVE-2025-53786, demonstrating privilege escalation in hybrid Microsoft Exchange environments via misconfigured trust…

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

CVE-2025-41115

harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)

Proof-of-concept exploit for CVE-2022-3172 in Kubernetes, demonstrating unauthorized access to metrics API via a crafted token.

Go-based exploit for CVE-2021-43858 targeting MinIO privilege escalation vulnerability. Executes against a specified IP and port to demonstrate the…

A proof-of-concept for CVE-2021-41805 which is a vulnerability in HashiCorp Consul Enterprise allowing for Remote Code Execution (RCE) with escalated…

VMware exploit

Proof of concept for VMware vCenter CVE-2024-37081, modified to enhance usability for security testing and validation of the vulnerability.

PoC exploit for insecure permissions in Contour v1.28.3 that retrieves a Kubernetes service account token and accesses the cluster API, demonstrating…

Proof-of-concept for CVE-2024-21626, a container escape vulnerability in runc, demonstrating exploitation techniques.

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…