
HashcatRosetta
Hashcat rule analyzer and interpreter - A Rosetta Stone for decoding hashcat rule syntax

Hashcat rule analyzer and interpreter - A Rosetta Stone for decoding hashcat rule syntax

A collection of CVE exploits, including Python PoCs and README files with instructions for reproducing and exploiting each vulnerability.

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel race condition enabling unprivileged writes to read-only files and privilege…

Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of…

Audit and educational toolkit for CVE-2026-5006, a Vault templated-policy slash-injection vulnerability. Includes a read-only audit script generating…

Technical advisory and proof-of-concept for CVE-2026-12513, an unauthenticated arbitrary file deletion via path traversal in Shared Files WordPress…

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing…

Proof-of-concept for CVE-2026-30480, a Local File Inclusion vulnerability in LibreNMS NFSen module, demonstrating path traversal to include arbitrary…

Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

poc and writeup for cve-2026-21440: a critical path traversal vulnerability in @adonisjs/bodyparser allowing arbitrary file writing

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Proof-of-concept script demonstrating an authenticated local file inclusion (LFI) vulnerability in Dolibarr via the objectdesc parameter, allowing…

Reproduction environment for CVE-2026-1312 with Docker-based setup and automated execution script for vulnerability testing and analysis.

Proof-of-concept exploit for CVE-2026-24126, an arbitrary file read in Weblate via SSH host argument injection, allowing authenticated admins to read…

Reproduction lab for CVE-2026-3304, a Multer async fileFilter race condition causing disk exhaustion via orphaned temp files. Includes vulnerable and…

Proof-of-concept exploit for CVE-2025-8081, an arbitrary file read in Elementor WordPress plugin, allowing authenticated admins to read sensitive…

Bio-Formats ≤ 8.3.0 performs unsafe Java deserialization of attacker-controlled .bfmemo cache files during image processing; crafted .bfmemo can…

Instrumented analysis and reproducibility materials for ECDSA timing leakage in OpenSSL CVE-2024-13176