
trivy
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Proof-of-concept exploit for CVE-2026-41900, an unauthenticated remote code execution in OpenLearnX via container volume mount, enabling /tmp…

POC code for CVE-2024-29510 and demo VulnApp

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

Proof-of-concept exploit for CVE-2025-49131, a sandbox escape in FastGPT allowing arbitrary file read/write, import bypass, and remote code execution…

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The…

Proof of concept code for Datadog Security Labs referenced exploits.

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

CVE-2021-21978 exp

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

* React2Shell-CVE-2025-55182

* React2Shell-CVE-2025-55182