
CVE-2026-43284-DIRTY-FRAG-
Technical analysis of CVE-2026-43284 (Dirty Frag), a Linux kernel xfrm ESP local privilege escalation enabling page-cache writes to read-only files…

Technical analysis of CVE-2026-43284 (Dirty Frag), a Linux kernel xfrm ESP local privilege escalation enabling page-cache writes to read-only files…

RingWraith: CVE-2026-33150 and CVE-2026-33179 — Use-After-Free and NULL Dereference in libfuse io_uring

Quickly find differences and similarities in disassembled code

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

Instrumented analysis and reproducibility materials for ECDSA timing leakage in OpenSSL CVE-2024-13176

Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.

Technical write-up for CVE-2026-77113, a path traversal in Apport's apport-unpack where crafted report keys escape the extraction directory and write…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Linux kernel local privilege escalation exploit for CVE-2026-31635 that corrupts page cache via RxRPC in-place decryption, overwrites read-only…

This project is a cybersecurity research and analysis project focused on CVE-2023-38831, a critical WinRAR vulnerability that allows attackers to…

Proof-of-concept for CVE-2026-30480, a Local File Inclusion vulnerability in LibreNMS NFSen module, demonstrating path traversal to include arbitrary…

poc and writeup for cve-2026-21440: a critical path traversal vulnerability in @adonisjs/bodyparser allowing arbitrary file writing

Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and…

A repository of proof-of-concept files demonstrating disclosed and patched vulnerabilities in pngcheck (2.4.0 - 3.0.1), including CVE-2020-27818,…

Exploit script for CVE-2021-22204, an RCE vulnerability in ExifTool via malicious DjVu files, targeting versions 7.44 to 12.23.

Proof-of-concept exploit for Ghostscript command injection (CVE-2023-36664) with payload generation and injection into EPS/PS files for code…

Proof-of-concept for CVE-2024-22641: ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted SVG files, demonstrating regex backtrack limit…