
CVE-2023-48795
Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4


Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC



Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection


Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

CVE-2026-25049


A basic PoC leak for CVE-2021-28663 (Internal of the Android kernel backdoor vulnerability)

Test for CVE-2000-0649, and return an IP address if vulnerable

Script fo testing CVE-2000-0649 for Apache and MS IIS servers

This is an Exploit App I made when solving the DocumentViewer challenge (CVE-2021-40724) from MobileHackingLab. It will download a libdocviewe_pro.so…

Tutorial of CVE-2022-37969 with focus on the methodology of Kernel exploitation, not CVE's internal causes