


🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Exploits CVE-2026-64849 in MLflow, providing a proof-of-concept attack for security researchers to validate vulnerable deployments.

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Collaborative application security testing between humans and agents via CLI and MCP

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

Proof-of-concept exploits for CVE-2026-56197 demonstrating remote code execution in Windows Admin Center, implemented in Python for vulnerability…

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM

Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled…