
CVE-2026-14856-TastyIgniter
CVE-2026-14856 TastyIgniter v4.3.0

CVE-2026-14856 TastyIgniter v4.3.0

POC for CVE-2025-29927

CVE-2011-3192 - Remote Apache DOS for Apache versions 1.3.x, 2.0.64 and below and 2.2.19 and below. Developed in 2011 by Antonius (ev1lut10n / w1sdom)

4gaBoards < 3.3.9 - User Information Disclosure

Path Traversal vulnerability in TahaBakhtari/SubtitleGenerator - CVE-2026-51592

PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary…

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

CVE-2026-64638 (XSS2shell) POC.

Proof-of-concept exploit for CVE-2026-25991, a blind SSRF in Tandoor Recipes' Cookmate import, allowing authenticated users to access internal…

Proof-of-concept exploit for CVE-2026-33033, a denial-of-service vulnerability in Django's MultiPartParser via base64 whitespace CPU amplification,…


TastyIgniter 3.0.7 allows XSS via the name field during user-account creation

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

CVE-2024-0406 POC using symlinks

Proof-of-concept demonstrating an encoding flaw in Apache HTTP Server mod_proxy that can bypass authentication via crafted encoded URLs.