
CVE-2026-65640-
WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

CVE-2026-9198利用代码

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…



my poc for CVE-2026-53787

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.


A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A wordlist of API names for web application assessments

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab