
CVE-2026-54433
Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

A Telegram Mass Surveillance Bot in Python

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Twitter Intelligence OSINT project performs tracking and analysis of the Twitter

FARO - Document Sensitivity Detector

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0

CVE-2021-21220 Exploitation infrastructure

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

POC for CVE-2025-55130

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…