
gobuster
Directory/File, DNS and VHost busting tool written in Go

Directory/File, DNS and VHost busting tool written in Go

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

Diagnostic tool to test XCP-ng dom0 exposure to CVE-2026-43284 (Dirty Frag) local privilege escalation via xfrm-ESP kernel subsystem, with automated…

Exploit tool for CVE-2025-9074, enabling unauthorized Docker API access for container escape, host file read/write, and arbitrary command execution…

Proof-of-concept demonstrating Host Header Injection leading to SAML authentication bypass in Apache Airflow's AWS Auth Manager, with token theft and…

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

Proof-of-concept demonstrating GPU container escape via character device file creation, enabling host GPU access in multi-tenant Kubernetes and HPC…

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

Proof-of-concept exploit for CVE-2024-0132 demonstrating TOCTOU-based container escape via NVIDIA Container Toolkit's library mounting mechanism,…

Proof-of-concept exploit for CVE-2024-21626 runc container breakout via leaked file descriptors and process.cwd manipulation, enabling host…

Proof-of-concept exploit for CVE-2024-0132 enabling container escape via NVIDIA container toolkit, allowing host filesystem access and Docker daemon…

PHP-based proof-of-concept exploit for CVE-2025-9074, enabling unauthenticated remote code execution via Docker Engine API with container escape,…

Proof-of-concept exploit for Kata Containers container escape (CVE-2020-2023) using mknod to modify guest filesystem and overwrite system binaries…

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

Proof-of-concept exploit for CVE-2024-21626, a runc container escape vulnerability allowing host file system access via crafted working directory in…

Proof-of-concept exploits for CVE-2024-21626, a Docker/runc container escape vulnerability, demonstrating multiple attack vectors to access and…