
hackerone-reports
Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Proof-of-concept exploit for CVE-2024-30088, a Windows kernel TOCTOU vulnerability in AuthzBasepCopyoutInternalSecurityAttributes enabling arbitrary…

research on finding the bug and fix of CVE-2026-84616 and CVE-2026-84607

Revocation persistence detection lab: when the password reset succeeds but the attacker never leaves. Reproduces the Strapi CVE-2026-22706…

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

macOS TCC bypass exploit leveraging insecure file rename in Music and TV apps to gain Full Disk Access by overwriting the TCC database via a symlink…

CVE-2024–27630 Reference

WinRar is a very widely known software for windows. Previous version of WinRaR was a vulnerability which has been patched in Feb-2019. Most of the…

Proof-of-concept exploit for CVE-2025-24118, an XNU kernel race condition bug enabling local privilege escalation via a setgid binary.

Docker-based proof-of-concept demonstrating a TOCTOU race condition exploit against sudo's Digest_Spec feature (CVE-2015-8239) using inotify for…