
sudotimewarp-cve-2026-96512-
Reproduction and PoC scripts for CVE-2026-96512 (SudoTimeWarp), where the caller's TZ shifts sudoers NOTBEFORE/NOTAFTER windows, plus mitigation…

Reproduction and PoC scripts for CVE-2026-96512 (SudoTimeWarp), where the caller's TZ shifts sudoers NOTBEFORE/NOTAFTER windows, plus mitigation…

Repository dedicated to CVE-2024-47875, providing proof-of-concept material and analysis for this specific vulnerability.

School project - Please use other repos for actual testing

Security advisory detailing broken access control in UZ801/ES-U3TS MifiService web API, allowing unauthenticated data extraction, config…

Low-impact probe for Citrix NetScaler CVE-2026-3055 (SAML IdP memory overread)

Ansible playbook for testing CVE-2026-31431, automating vulnerability verification and configuration auditing in production environments.

Simple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Scanner and exploit tool for CVE-2026-22730, a SQL injection in Spring AI's MariaDB vector store. Supports time-based detection, GET/POST methods,…

Authenticated SQL injection scanner for Koha Library Management System (CVE-2026-31844) using boolean-based blind technique to verify vulnerability…

Batch vulnerability scanner for CVE-2026-39363 in Vite dev server, exploiting WebSocket origin validation bypass to read arbitrary files via…

Nuclei template for detecting CVE-2026-1107 in EyouCMS, exploiting path traversal in check_userinfo to read arbitrary files and potentially achieve…

Exploit script for CVE-2026-0740 targeting Ninja Forms file upload endpoints to upload a PHP shell, scanning a list of URLs and logging successful…

Automated SSH-based scanner and patcher for Linux kernel LPE vulnerabilities CVE-2026-43284 and CVE-2026-43500, with multi-host discovery, privilege…

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

Proof-of-concept for CVE-2026-12352, an authentication bypass in Digi PortServer TS that discloses device configuration including plaintext RADIUS…

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…