
CVE-2021-3281
Proof-of-concept for CVE-2021-3281: directory traversal vulnerability in Django's TarArchive utility via crafted tar files, with Python tarfile…

Proof-of-concept for CVE-2021-3281: directory traversal vulnerability in Django's TarArchive utility via crafted tar files, with Python tarfile…

Python CVE-2018-1000802 Proof-of-Concept

Tarfile module directory traversal vulnerability ( with overflow crossed Directory ) --> Lead to Privilege escalation

CodeQL query test for CVE-2023-24329, demonstrating static analysis detection of a specific vulnerability in Python's urllib.parse module.

Proof-of-concept exploit code for CVE-2026-20805, demonstrating the vulnerability for security research and validation.

CVE‑2025‑4517 Proof‑of‑Concept Script

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module…

Proof-of-concept module for CVE-2026-54121 (Certighost), exploiting AD CS enrollment validation via rogue LDAP/SMB listeners to impersonate a Domain…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Static code audit of CVE-2024-57521, an authenticated SQL injection in RuoYi-Vue's generator module, with source-to-sink analysis and a %0b filter…

GreyEnergy Mini Module Malware Analysis (Turkish)

Proof-of-concept for CVE-2026-30480, a Local File Inclusion vulnerability in LibreNMS NFSen module, demonstrating path traversal to include arbitrary…

CVE-2026-24419 - OpenSTAManager has a SQL Injection in the Prima Nota module

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

Technical analysis of CVE-2025-37899: a use-after-free vulnerability in Linux kernel's ksmbd SMB module enabling remote code execution. Includes…

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content