
CVE-2026-22738-POC
Proof-of-concept exploit for CVE-2026-22738, a critical SpEL injection RCE in Spring AI SimpleVectorStore, demonstrating unauthenticated OS command…

Proof-of-concept exploit for CVE-2026-22738, a critical SpEL injection RCE in Spring AI SimpleVectorStore, demonstrating unauthenticated OS command…

Technical analysis and proof-of-concept exploit for CVE-2025-59287, a critical RCE in Windows Server Update Services via unsafe deserialization,…

Educational analysis and proof-of-concept code for CVE-2021-4034 (pkexec local privilege escalation), with detailed comments explaining the…

Bu depo, Linux cekirdeginde (kernel) bulunan CVE-2026-31431 (Copy Fail) zafiyetini icermektedir. Zafiyet, algif_aead modülündeki bir optimizasyon…

Stored XSS vulnerability in InvoicePlane 1.7.0 via unsanitized invoice number field, with proof-of-concept and remediation details.

Hi, I’m K, This is my first CVE, which is a Remote Code Execution (RCE) vulnerability. It is the beginning of my journey as a security researcher.

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo versions 1.9.14-1.9.17, with precompiled library and remediation…

All stages of exploring the polkit CVE-2021-4034 using codeql

Analysis and proof-of-concept for CVE-2021-44142, a Linux kernel vulnerability, providing technical details and exploitation research.

Proof of concept (builder) for CVE-2026-39973 (apktool)

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text()…

Academic proof-of-concept demonstrating CVE-2026-21445 [LangFlow] for authorized security research.

Proof of Concept demonstrating CVE-2025-8760, with a detailed technical write-up explaining the vulnerability and exploitation methodology.

This repository contains a professional write-up of a path traversal vulnerability discovered in InvenTree's report template engine. This…

Proof-of-concept exploit for CVE-2026-27199, a Werkzeug safe_join() Windows device-name bypass, demonstrating path traversal and silent data discard.

Educational proof-of-concept for CVE-2026-666, a remote code execution vulnerability in ShadowWeb Framework's deserialization, with technical details…

Vulnerability in D2L Brightspace's Learning Management System(LMS)