
CVE-2026-58138
Defensive security research repository detailing CVE-2026-58138, an unauthenticated RCE in Conductor via GraalVM. Provides technical analysis,…

Defensive security research repository detailing CVE-2026-58138, an unauthenticated RCE in Conductor via GraalVM. Provides technical analysis,…

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

CVE-2026-72898

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

CVE Reproduction: cve-2025-55182-react2shell_reproduction

AWS WAF Solver, full reverse implemented in 100% Python & Golang.

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

[CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal

CVE-2021-3441 CVE Check is a python script to search targets for indicators of compromise to CVE-2021-3441

Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as…

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

Walkthrough of detecting, investigating, and responding to a CVE-2024-24919 path traversal attack, including log analysis, threat intel checks, and…