
0day-Rubbish
Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Technical vulnerability analysis and CVE briefing for CVE-2026-9645 affecting ScadaBR.

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…


There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript


Public exploit for CVE-2025-38001

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656

OpenPLC Runtime suffers from a persistent denial of service (DoS) vulnerability in the /upload-program-action endpoint.

Authenticated users can upload arbitrary files (e.g. .html, .svg) as profile images in OpenPLC Runtime. These files are publicly accessible without…

CVE-2025-41646 - Critical Authentication bypass

SpiderControl SCADA Web Server File Upload Vulnerability

Proof Of Concept for the CVE-2012-1831 (Kingview Touchview 6.53). This is a Industrial Control Systems Vulnerability

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.