
security-research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

Educational security research repository for CVE-2025-9974, providing vulnerability awareness material and authorized lab guidance for controlled…

Educational security research repository documenting CVE-2026-65660 with setup guidance for authorized lab testing and vulnerability awareness.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Educational CVE research repository for CVE-2026-94545, providing proof-of-concept material and lab guidance for authorized vulnerability analysis…

Educational CVE-2026-90898 proof-of-concept repository for authorized security research, vulnerability awareness, and defensive testing in isolated…

The Browser Exploitation Framework Project

Proof-of-concept exploit for CVE-2026-68376 in Ubuntu kernel 7.0.0-30, leveraging SCTP chunk handling and PTE manipulation to escalate privileges to…

Educational security research repository for learning and testing CVE-2026-93485 concepts in isolated, authorized lab environments.

PoC exploit and scanner for CVE-2026-89026, validating the Issabel PBXAPI authentication bypass via forged HS256 JWTs across single or listed targets.

Proof-of-concept and educational research repository for CVE-2026-74469 (DiagSpill), providing vulnerability analysis material for authorized lab…

Proof-of-concept for CVE-2026-68121 (PPPoEject), providing a Python exploit implementation for authorized security research and lab testing.

Educational CVE-2026-81000 proof-of-concept repository for authorized security research, vulnerability awareness, and controlled lab testing.

Proof-of-concept and research repository for CVE-2026-80844 (DirtyAH6), providing educational material and lab setup guidance for authorized…

Docker-based lab reproducing CVE-2023-27163 SSRF in Request-Baskets, with exploitation verification, detection script, and network-isolation…

Docker-based lab demonstrating CVE-2019-15107, the Webmin unauthenticated RCE, covering deployment, exploitation, detection, and remediation.

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Docker-based lab reproducing CVE-2024-31218, an unauthenticated PocketBase admin creation flaw in Webhood, with PoC, detection, and remediation…