
CVE-2025-54962
Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

Let's control Secure Boot Chain ourselves.

CVE-2017-8291 CTF with docker and examples


Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including…

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

A POC on how to exploit CVE-2022-27518

Proof-of-Concept for CVE-2024-52005: ANSI escape sequence injection in Git. Demonstrates incorrect 'not_affected' VEX claims in hardened container…


Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

https://hackerone.com/reports/865652

Generates WebP images that trigger CVE-2023-4863 heap buffer overflow in libwebp, using tunable OFFSET/VALUE constants for exploit testing and…

Integer overflow in Apple ImageIO WebP parsing (macOS/iOS)

This exploit targets CVE-2019-14811 in GS environments where PostScript output is not reflected, but is executed such as PDF previews via png images.


A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.
