
awesome-incident-response
Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Quickly find differences and similarities in disassembled code

Proof-of-concept exploit and writeup for CVE-2022-44789, a heap buffer overflow in MuJS JavaScript interpreter, including vulnerable version and…

A brief report on CVE-2016-4117 (A vulnerability in Adobe Flash)

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

Instrumented analysis and reproducibility materials for ECDSA timing leakage in OpenSSL CVE-2024-13176

poc and writeup for cve-2026-21440: a critical path traversal vulnerability in @adonisjs/bodyparser allowing arbitrary file writing

A repository of proof-of-concept files demonstrating disclosed and patched vulnerabilities in pngcheck (2.4.0 - 3.0.1), including CVE-2020-27818,…

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring

Technical write-up for CVE-2026-77113, a path traversal in Apport's apport-unpack where crafted report keys escape the extraction directory and write…

Proof-of-concept exploit for Ghostscript command injection (CVE-2023-36664) with payload generation and injection into EPS/PS files for code…

Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and…

Spipu Html2Pdf < 5.2.8 - XSS vulnerabilities in example files

Linux kernel local privilege escalation exploit for CVE-2026-31635 that corrupts page cache via RxRPC in-place decryption, overwrites read-only…

Proof-of-concept for CVE-2021-3281: directory traversal vulnerability in Django's TarArchive utility via crafted tar files, with Python tarfile…

Proof-of-concept for CVE-2024-22641: ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted SVG files, demonstrating regex backtrack limit…