
CVE-2026-41096-PoC
Proof-of-concept exploit for CVE-2026-41096, demonstrating the vulnerability and providing a reproducible test case for security researchers and…

Proof-of-concept exploit for CVE-2026-41096, demonstrating the vulnerability and providing a reproducible test case for security researchers and…

Proof-of-concept research repository for CVE-2026-42978, containing analysis and exploit code for the referenced vulnerability.

Proof-of-concept exploit for CVE-2026-66804, a privilege escalation vulnerability in the CrossDevice Service component.

Writeup and proof-of-concept for CVE-2026-83991, documenting the vulnerability details and demonstrating exploitation.

Technical analysis of CVE-2008-0166 in Bitcoin 2009-2012, examining OpenSSL 0.9.8c PRNG weaknesses, Windows entropy failures, and key-space…

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

Collection of detailed and optimized(?) write-ups for various CTF challenges

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Technical writeup analyzing CVE-2024-20154, a stack-based buffer overflow in MediaTek MT6769 NB-IoT baseband firmware, covering reverse engineering…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Educational CVE-2016-3223 proof-of-concept repository for authorized security research, vulnerability awareness, and lab-based testing in isolated…

Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing…

Research repository documenting BlueFrag (CVE-2020-0022) Android Bluetooth heap overflow experiments, including GDB crash analysis and memcpy…

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

Docker-based lab and Python exploit for CVE-2026-18963, a Keycloak reset-credentials flow bypass enabling account takeover via email verification…

Docker lab environment with PoC exploit and checker for CVE-2026-20253, a pre-auth RCE in Splunk Enterprise via the PostgreSQL sidecar service.

Docker lab reproducing the FOSSBilling pre-auth RCE chain (CVE-2026-27604 auth bypass + CVE-2026-28496 Twig SSTI) with a Python PoC and patched…