
noPac
Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287

Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287

Hardened container staging framework with seccomp syscall whitelisting and eBPF telemetry to detect and block container escape and kernel ULP…

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

Fork of https://github.com/hakaioffsec/CVE-2024-21338

Browser-based MCP CTF — OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.

Proof-of-concept exploit for CVE-2025-7771, a Windows kernel driver vulnerability in ThrottleStop.sys enabling arbitrary physical memory read/write…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Proof-of-concept for CVE-2020-24029: unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege…

CVE-2024-45264

TP-LINK Multiple HTML Injection Vulnerabilities

Extract ASN information about a given company