
CVE-2026-43867
Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Proof-of-concept and analysis for CVE-2025-32711

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Linux, macOS and Windows Install scripts for cnquery & cnspec

A collection of my public security advisories.

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

A tutorial on how to detect the CVE 2024-3094

Reproducer for CVE-2026-46456 — Apache Camel camel-aws2-sqs inbound message-attribute header injection (Camel control-header injection via…

Proof-of-Concept for CVE-2024-47066

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

CVE-2020-10749 PoC (Kubernetes MitM attacks via IPv6 rogue router advertisements)

Suppress vulnerabilities applying Kubernetes context to scans

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…

CVE-2026-40564: SSRF via FlinkSessionJob jarURI in apache/flink-kubernetes-operator. Self-contained reproducer that runs on a local kind cluster with…