
CVE-2024-27198-EXPLOIT
A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass

A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

A centralized resource for previously documented WDAC bypass techniques

Python tarfile data filter bypass via PATH_MAX overflow in os.path.realpath() - CVE-2025-4517 / CVE-2025-4330

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)

Java-based exploit for CVE-2022-25845 (Fastjson auto-type bypass RCE) with accompanying analysis PDF and reference articles for educational study.

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

Responsible disclosure of unpatched vulnerability in FluentCRM by WPManageNinja

GNU IFUNC is the real culprit behind CVE-2024-3094

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Proof of concept of CVE-2017-0807

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

A list of public penetration test reports published by several consulting firms and academic security groups.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Automated Penetration Testing Agentic Framework Powered by Large Language Models

Advisories, proof of concept files and exploits that have been made public by @pedrib.