
CVE-2026-20896
Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

Tool for embedding payloads into JPG/PNG format images, allowing to perform certain actions when opening them.

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

Kali Linux VM images build script

Kali Linux ARM build scripts https://arm.kali.org/

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

Extract registry and NTDS secrets from local or remote disk images

Black-box security evaluation of five ISP cable modem/router gateways, analyzing firmware images and documenting 35+ vulnerabilities including…

Pentester-focused Docker registry tool to enumerate and pull images

Python utility to check if Android verified boot images (vbmeta) are signed with publicly known test keys, identifying misconfigurations in release…

Local privilege escalation exploit for CVE-2025-6019 using crafted XFS filesystem images to gain root shell access on Linux systems.

the task from C*****k

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

Helper scripts to remaster Linux Live CD images for the purpose of creating ready to use security wargames with pre-installed vulnerabilities to…

This exploit targets CVE-2019-14811 in GS environments where PostScript output is not reflected, but is executed such as PDF previews via png images.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

Python-based exploit generator for CVE-2023-38831 WinRAR vulnerability. Creates malicious RAR archives with bait files (PDF, images) and payload…

Technical analysis and proof-of-concept for CVE-2025-6019, a local privilege escalation vulnerability in libblockdev and udisks2, enabling root…