
CVE-2025-9074
PHP poc, exploit for CVE-2025-9074

PHP poc, exploit for CVE-2025-9074
Proof-of-concept for CVE-2024-21626, a runc container escape vulnerability. Includes verification scripts, two exploitation methods (cron reverse…

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Proof-of-concept exploits for CVE-2019-5736, a runC container escape vulnerability, demonstrating container breakout via malicious images and exec…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Proof-of-concept exploit for CVE-2026-41900, an unauthenticated remote code execution in OpenLearnX via container volume mount, enabling /tmp…

Bash-based exploit script for CVE-2025-9074 that abuses the internal Docker API to mount the host C drive, execute commands inside a container, and…

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

POC code for CVE-2024-29510 and demo VulnApp

Exploit the dirtycow vulnerability to login as root

Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Exploit CVE-2025-1974 with a single file.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…