
CVE-2026-0303
Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis…

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

CVE-2025-66516 working exploit, scanner, explanation.

Minimal verification lab for CVE-2025-66516 (Apache Tika XXE). Generates malicious PDF payloads and validates the vulnerability by reading sensitive…

Reproducible lab demonstrating CVE-2025-55182 Remote Code Execution against Next.js 16.0.0 with React Server Components, including external exploit…

Docker-based lab demonstrating CVE-2025-58360, a critical unauthenticated XXE injection in GeoServer WMS/OWS services. Includes exploit script for…

Bash script for Privilege Escalation via "ndsudo" (Netdata Local Exploit)

Comprehensive Android security vulnerability demonstrations featuring CVE-2017-13156 (Janus), broadcast receiver exploitation, external storage…


Kirby < 3.9.6 XML External Entity exploit