
patchy
Automated Persistence and Lateral Movement using GCP Patch Management

Automated Persistence and Lateral Movement using GCP Patch Management

Reproducer for CVE-2026-46456 — Apache Camel camel-aws2-sqs inbound message-attribute header injection (Camel control-header injection via…


MiniO verify interface sensitive information disclosure vulnerability (CVE-2023-28432)

Proof of concept about the privilege escalation flaw identified in Google's Osconfig

Toolkit for CVE-2025-55182, also known as React2Shell.


CVE-2026-20182 PoC - Cisco Catalyst SD-WAN Controller / Manager Authentication Bypass (CVSS 10.0)

Proof-of-Concept for CVE-2024-47066

CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Apache Kafka客户端未对用户输入进行严格验证和限制,未经身份验证的攻击者可通过构造恶意配置读取环境变量或磁盘任意内容,或向非预期位置发送请求,提升REST API的文件系统/环境/URL访问权限。

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

Local Privilege Escalation in Amazon WorkSpaces via TOCTOU and Arbitrary File Write

Proof of Concept for CVE-2025-27136 (XXE in Local-S3)

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

MinIO Information Disclosure Vulnerability scanner by metasploit