
CVE-2022-1040
This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication

This vulnerability allows an attacker to gain unauthorized access to the firewall management space by bypassing authentication

Proof-of-concept exploit for CVE-2020-25747 demonstrating unauthenticated remote access to RTSP and ONVIF services on Rubetek RV-3406/3409/3411…

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

Proof-of-concept exploit for CVE-2023-0179 targeting Linux kernel privilege escalation. Includes build instructions and a compiled binary to achieve…

Proof-of-concept exploit for CVE-2021-3490, a Linux kernel eBPF vulnerability that enables local privilege escalation to root on Ubuntu 20.04 with…

Stack overflow exploit for CVE-2022-0435 in the TIPC module, providing local privilege escalation to root on Ubuntu kernels.

IC Realtime ICIP-P2012T is vulnerable to Incorrect Access Control via an open port

IC Realtime ICIP-P2012T 2.420 is vulnerable to Incorrect Access Control

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in tawk.to Live Chat 1.6.1, demonstrating JavaScript injection via unsanitized…

Proof-of-concept for CVE-2026-31431 demonstrating live process code injection via page cache, achieving arbitrary code execution in a running process…

Xss In Tawk.to Live Chat Support (CVE-2025-57483)

CVE-2026-31431 (Copy Fail) novel exploit: live code corruption via page cache. Overwrites libc exit() code through MAP_PRIVATE page sharing — affects…