
CVE-2026-58455-PoC
PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

PoC for CVE-2026-58455: Dockwatch <=0.6.567 unauthenticated RCE. Stdlib-only Python.

Safe educational simulation of CVE-2025-27520 with a Flask vulnerable service and Python PoC scanner for demonstrating deserialization and broken…

Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploitability…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Proof of Concept code for proving CVE-2024-40635 vulnerability

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

A repo to automatically generate and keep updated a series of Docker images through GitHub Actions.

Detections for CVE-2021-44228 inside of nested binaries

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

A collection of scripts, and tips and tricks for hacking k8s clusters and containers.

A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing