
CVE-2022-0847-Dirty-Pipe-
this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"

this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline:…

Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the…

Go port of the Copy Fail PoC for CVE-2026-31431, a Linux kernel authencesn flaw enabling a 4-byte write into page cache via AF_ALG and splice.…

craft aggregation pipeline to access data without proper authorisation due to improper handling of $mergeCursors in MongoDB >v8.0 <8.0.7, >v7.0…

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

Technical breakdown of CVE-2026-3854, a GitHub RCE via header injection in git push, explaining the vulnerability, exploitation technique, and…

Proof-of-concept exploit for CVE-2024-21542 demonstrating arbitrary file write via Zip Slip in Luigi pipeline manager. Generates malicious archives…

POCs to demonstrate CVE-2026-42167 in ProFTPD

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Scope-aware bug bounty pipeline for CVE-2025-0133 (Palo Alto PAN-OS GlobalProtect reflected XSS). Shodan → H1/BC scope match → safe canary validation…

Automated XSS validation pipeline for CVE-2020-3580 with Shodan-based discovery, scope matching, and approval-gated canary testing for Cisco ASA/FTD…

GitHub Actions Pipeline Enumeration and Attack Tool

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…