
BrowserBox
💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

💚🇺🇸🗽Secure remote browsing anywhere, any way you like it.

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

[CVE-2024-26581] Vulnerability Checker for BGN Internal

CVE-2026-66804 Windows Cross Device virtual camera EoP - private internal research repository

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Dockerized reproduction of CVE-2026-59774 for Gitea; demonstrates path traversal in go-org markup include to read arbitrary files and escalate to RCE…

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

Proof-of-concept for CVE-2026-11106 exploiting unrestricted DNS AXFR zone transfers to enumerate domain records, expose internal hosts, and leak…



Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)