
DirtyPipe-Exploit
Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe) enabling local privilege escalation on Linux kernels 5.8 through 5.16.10 by overwriting…

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe) enabling local privilege escalation on Linux kernels 5.8 through 5.16.10 by overwriting…

AI-agent skills for distributed-systems testing

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

Technical Details and Exploit for CVE-2025-50461

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Detailed disclosure of CVE-2025-47423: Local File Inclusion in Personal Weather Station Dashboard 12_lts. Includes PoC, vulnerable code analysis, and…

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

Proof-of-concept for CVE-2025-66024: Stored XSS in XWiki Blog Application via unescaped post title in HTML title tag. Includes reproduction steps,…

Documentation and reproduction code for CVE-2025-67221, a denial-of-service vulnerability in orjson's dumps() function caused by uncontrolled…

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the…

Proof-of-concept exploit for CVE-2025-64720, a libpng buffer overflow in palette premultiplication. Includes exploit generator, test harness with…

Proof-of-concept for open redirection via Host header manipulation in Sielox AnyWare 2.1.2 (CVE-2024-34328), with exploit steps, impact, and…