
CVE-2026-41940-analysis
Technical analysis of the cPanel/WHM auth bypass

Technical analysis of the cPanel/WHM auth bypass

A Highly Accessible and Automated Virtualization Platform for Security Education

CTF-style Docker lab for CVE-2026-41651 (Pack2TheRoot): PackageKit permissive-polkit local privilege escalation

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.


Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).

vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

Exploiting the vulnerability called "Dirty_Sock" (CVE-2019-7304) in the REST API for Canonical's snapd daemon.

Classic stack-based buffer overflow in War FTP Daemon 1.65 demonstrating old-school remote code execution through malformed FTP commands.

Proof-of-concept exploit for CVE-2025-32433, a pre-authentication RCE in Erlang/OTP SSH daemon. Includes Python script to send crafted SSH channel…

ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

Local privilege escalation exploit targeting PackageKit's TOCTOU race condition (CVE-2026-41651). Escalates from unprivileged user to root via polkit…

FortiOS buffer overflow vulnerability

Proof-of-concept exploit for CVE-2026-52199: unauthenticated remote code execution via exposed ADB daemon on UZ801 4G LTE router. Includes…