
CVE-2026-49975-HTTP-2-Bomb
Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to…

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to…

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Advisory: CVE-2026-38361 multiple DoS vulnerabilities (CWE-400/CWE-670) in dash-uploader (Python/PyPI)

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of…

Detection for CVE-2025-7775


A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

PoC for Nginx 0.6.18 - 1.20.0 Memory Overwrite Vulnerability CVE-2021-23017

Update the old POC of CVE-2025-5777 Citrix NetScaler Memory leak

An example exploit for CVE-2017-7376


PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause…


CVE-2025-24201 WebKit Vulnerability Detector (PoC)


MongoBleed CVE-2025-14847 Vulnerability Checker