
CVE-2026-63292
Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

Advisory and PoC for CVE-2026-103648, a path traversal (CWE-22) in image-downloader 4.3.0 enabling arbitrary file write, with root-cause analysis,…

PoC and patch verification notes for CVE-2026-100380, a reflected XSS in Wikibase language-validation error pages, with a script that detects…

Defensive research documentation for CVE-2026-86950, an Apple CoreGraphics out-of-bounds write, covering vulnerability triage, affected versions,…

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

Fix-Like Artifacts With Embedded Defects

Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

Proof-of-concept exploit for CVE-2024-21338, a Windows AppLocker driver (appid.sys) privilege escalation vulnerability used by Lazarus group as a…

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

Reverse engineering notes and working PoC for CVE-2026-84568, a macOS automountd trust-boundary violation allowing mounts from localhost or the…

CVE-2026-25541 impact analysis for Fuel infrastructure (bytes crate integer overflow)

CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6