
CVE-2022-27518_POC
A POC on how to exploit CVE-2022-27518

A POC on how to exploit CVE-2022-27518

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including…

Let's control Secure Boot Chain ourselves.


CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

Statamic CMS versions <4.33.0 vulnerable to "Remote Code Execution"


The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.


A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

CVE-2017-8291 CTF with docker and examples


This exploit targets CVE-2019-14811 in GS environments where PostScript output is not reflected, but is executed such as PDF previews via png images.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

https://hackerone.com/reports/865652