
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

Proof of concept code for Datadog Security Labs referenced exploits.

CVE-2021-21978 exp

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The…

POC code for CVE-2024-29510 and demo VulnApp

* React2Shell-CVE-2025-55182

* React2Shell-CVE-2025-55182

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213