
CVE-2026-39987
Proof-of-concept exploit for Marimo pre-authentication RCE. Uses the unauthenticated /terminal/ws WebSocket endpoint to spawn a PTY and establish a…

Proof-of-concept exploit for Marimo pre-authentication RCE. Uses the unauthenticated /terminal/ws WebSocket endpoint to spawn a PTY and establish a…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Oracle OID LDAP Server Privileges Management Exploit

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Redis UAF RCE PoC collection for CVE-2026-23479: safe version checker, exploit module, GDB-assisted PoC, and Sigma detection rules for authorized…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

4gaBoards < 3.3.9 - User Information Disclosure

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

Python scripts for detecting and exploiting OpenSSL Heartbleed (CVE-2014-0160), leaking sensitive memory contents from vulnerable TLS services.

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…