### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-4x34-chg5-mwjj. This link is maintained to preserve external references. ### Original Description The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if errors were encountered on previous files, such as 'Operation not permitted'. Scripts relying on these exit codes may proceed under a false sense of success while sensitive files remain with restrictive or incorrect permissions.
PoC: TLPE
CVE-2026-49881, a logic issue in the InCallController class in Android 17's Telecom service that allows an unprivileged app to gain arbitrary code execution as UID 1000 system_server
PoC: mikrotrick-poc
CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC
PoC: cve-2026-75650-magento-validation-lab
Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.
PoC: POC-AIOWPM-CVE-2026-19949
PoC funcional de CVE-2026-19949 (AIOWPM): SQLi de segundo orden no autenticada en All-in-One WP Migration <= 7.109 via regex de replace_table_values. Laboratorio Docker + payload derivado (leak de ai1wm_secret_key por REST anonima) + RCE con importacion anonima.
PoC: CVE-2026-28576-poc
SQL injection vulnerability in Android 17 (AOSP)
PoC: KeySniper
**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.
PoC: CVE-2026-62201-OpenClaw-SSRF
Deep-dive analysis of CVE-2026-62201: OpenClaw sandbox exec-server network policy bypass (SSRF). Root cause, vulnerable vs patched code, exploitation, detection, remediation.
PoC: Certighost_CVE-2026-54121
AD CS 证书身份伪造漏洞,属于ESC(Exploit Certification)系列 的新成员
PoC: CVE-2026-83991-writeup-and-poc
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83991
PoC: CVE-2026-19089-WooCommerce-Tyche
CVE-2026-19089 WooCommerce Tych Remote Command Execution
PoC: GhostLock-NVIDIA-Shield-9.2.4
Validated GhostLock CVE-2026-43499 port for NVIDIA Shield TV Pro mdarcy 9.2.4
PoC: CVE-2025-8110
CVE-2025-8110 - Gogs <=0.13.x symlink bypass -> arbitrary file write as the Gogs process user
PoC: CVE-2025-58434
CVE-2025-58434 - Flowise (CVE-2025-58434) unauthenticated account takeover via password-reset token disclosure
PoC: CVE-2025-55182
CVE-2025-55182 - React2Shell (CVE-2025-55182) unauthenticated RCE via React Server Components Flight deserialization
PoC: ClickHouse-Native-JDBC
Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind "Checksum doesn't match: corrupted data" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.
PoC: CVE-2026-39987
Marimo Pre Authentication RCE
PoC: sift-hardened
Security-hardened fork of sift 17.1.3 for CVE-2026-85625. Not affiliated with crcn/sift.js.
PoC: CVE-2026-82222
⚡ GHOSTLYR00T - CVE-2026-82222 GiveWP RCE Exploit Framework Unauthenticated RCE on GiveWP <= 4.16.7.1. Mass scanning, auto-detection (form/gateway/amount), multi-threading, JSON/TXT output, interactive shell. CVSS 9.8 Critical. ⚠️ Authorized testing only.
PoC: CVE-2026-85046
CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82
PoC: CVE-2026-74239
Sanitized XenForo write-up and proof of concept for CVE-2026-74239.
PoC: CVE-2026-73321
Sanitized XenForo write-up and proof of concept for CVE-2026-73321.
PoC: CVE-2026-73320
Sanitized XenForo write-up and proof of concept for CVE-2026-73320.
PoC: CVE-2026-73319
Sanitized XenForo write-up and proof of concept for CVE-2026-73319.
PoC: CVE-2026-73318
Sanitized XenForo write-up and proof of concept for CVE-2026-73318.
PoC: CVE-2026-73317
Sanitized XenForo write-up and proof of concept for CVE-2026-73317.
PoC: CVE-2026-73316
Sanitized XenForo write-up and proof of concept for CVE-2026-73316.
PoC: CVE-2026-73315
Sanitized XenForo write-up and proof of concept for CVE-2026-73315.
PoC: CVE-2026-73314
Sanitized XenForo write-up and proof of concept for CVE-2026-73314.
PoC: CVE-2026-73313
Sanitized XenForo write-up and proof of concept for CVE-2026-73313.
PoC: CVE-2026-73312
Sanitized XenForo write-up and proof of concept for CVE-2026-73312.
PoC: CVE-2026-73311
Sanitized XenForo write-up and proof of concept for CVE-2026-73311.
PoC: CVE-2026-73310
Sanitized XenForo write-up and proof of concept for CVE-2026-73310.
PoC: CVE-2026-73309
Sanitized XenForo write-up and proof of concept for CVE-2026-73309.
PoC: guardskill
Read-only scanner for git settings that let a repository run code in coding agents (Claude Code, Codex, Cursor, Copilot). Covers the GitSpawn class and CVE-2026-45033. No dependencies, no network, no telemetry.
PoC: cve-2010-4221-lab
From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented
PoC: netty-http-check
CVE-2026-59903 / CVE-2026-33870: offline checker for the 14 io.netty:netty-codec-http CVEs. Netty ships all modules under one version number but each has its own fix version — 4.1.136.Final (the netty-codec-http2 answer) still leaves this module exposed; it needs 4.1.137.Final / 4.2.17.Final.
PoC: metasploit-lab-report
Educational penetration testing lab report demonstrating exploitation of vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523) in Metasploitable 2 using Metasploit Framework. Includes detailed documentation of reconnaissance, vulnerability analysis, configuration, verification, and exploitation phases.
PoC: CVE-2026-8069
Technical write-up and PoC for CVE-2026-8069 in Acer NitroSense and PredatorSense
PoC: stylesmuggler-adobe-patches-mageos
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Mage-OS stores, via cweagans/composer-patches. Companion to stylesmuggler-adobe-patches (Magento).
PoC: CVE-2026-8732-PoC
CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation
PoC: stylesmuggler-adobe-patches
composer require delivery of Adobe's official APSB26-146 (CVE-2026-75650) fix for Magento, via cweagans/composer-patches. Auto-selects the patch for your Magento version.
PoC: cve-2026-40369-exploit
Exploit inspired by `https://voidsec.com/cve-2026-40369-browser-sandbox-escape/`. Use Feature_RestrictKernelAddressLeak and forge token to Elevate privileges
PoC: CVE-2026-83548-CVE-2026-83549
CVE-2026-83548, CVE-2026-83549, - Draft or TODO - https://github.com/rapid7/metasploit-framework/pull/21883
PoC: hdwebmobile-booking-appointments
Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.
PoC: CVE-2026-52307
Public reference for CVE-2026-52307
PoC: CVE-2026-10795
CVE-2026-10795 - Draft or TODO
PoC: CVE-2025-47981
Assessment script — CVE-2025-47981 SPNEGO NEGOEX heap overflow (CVSS 9.8, wormable). Checks ntoskrnl.exe version, PKU2U registry key, exposed ports. Detection only · KB5062560 · July 2025.
PoC: log4shell-exploitation-detection
Log4Shell (CVE-2021-44228) exploitation from a Kali VM against a vulnerable containerized app, with Splunk-based detection engineering and validated remediation. Covers the full attack lifecycle: exploitation, JNDI and host-level auditd detection, and before/after remediation proof.
PoC: cve-2015-3306-lab
Reproducible Docker lab + raw-socket exploit for CVE-2015-3306 (ProFTPD mod_copy pre-auth arbitrary file copy) — a patch-diffing learning exercise
PoC: CVE-2026-69451-PoC
PoC for the CVE-2026-69451 - Fastprox EoP
PoC: CVE-2026-39987-PoC
CVE-2026-39987 Proof of Concept
PoC: misfortune-cookie
This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).
PoC: CVE-2026-77276-PoC
CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online
PoC: CVE-2023-52356-libtiff-analysis
Root-cause analysis and patch validation of CVE-2023-52356 in libtiff using AddressSanitizer and GDB.
PoC: BlueGate-CVE-2020-0609
BlueGate Exploit validator - RD Gateway validator for CVE-2020-0609 and CVE-2020-0610 (BlueGate) using OpenSSL DTLS over UDP/3391.
PoC: CVE-2022-4140
WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read
PoC: CVE-2026-81780-Hash-Form
CVE-2026-81780 — Hash Form RCE
PoC: CVE-2026-82329-JFrog-Artifactory-
CVE-2026-82329 — JFrog Artifactory Auth Bypass
PoC: cs50-cybersecurity-final-project
CS50 Cybersecurity Final Project: Technical Analysis of the XZ Utils Backdoor (CVE-2024-3094)
PoC: gha-lab-00d54c717d
Security-research lab: CVE-2026-47172 (workflow_run pwn request in deploy.yaml) — flattened snapshot of duck-organization/questbot at 1903b2f
PoC: stylesmuggler-ioc-toolkit
StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells, persistence artifacts, and known indicators of compromise.
PoC: CVE-2026-33234
SSRF via smtplib raw TCP sockets bypassing HTTP blocklist in AutoGPT SendEmailBlock
PoC: CVE-2025-5548
Buffer overflow in FreeFloat FTP Server 1.0
PoC: gitssrf-gim-cve-parent
gitssrf-gim CVE-2025-48384 parent
PoC: 2009
Linux Kernel Exploits -> CVE-2009-1185 + CVE-2009-1337 + CVE-2009-2692 + CVE-2009-2698 + CVE-2009-3547
PoC: 2008
Linux Kernel Exploits -> CVE-2008-0600 + CVE-2008-0900 + CVE-2008-4210
PoC: 2006
Linux Kernel Exploits -> CVE-2006-2451 + CVE-2006-3626
PoC: CVE-2026-86218
CVE-2026-86218 - Draft or TODO - N-central is vulnerable to a pre-auth remote code execution
PoC: 2005
Linux Kernel Exploits -> CVE-2005-0736 + CVE-2005-1263
PoC: 2004
Linux Kernel Exploits -> CVE-2004-0077 + CVE-2004-1235 + caps_to_root
PoC: galaxy-a37-root
CVE-2026-43499 exploit payload for Samsung Galaxy A37 (A376BXXS4AZG4, kernel 6.1.138-android14-11)
PoC: CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184
CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184
PoC: exploit-mikrotik-2026
CVE-2026-67276 MikroTik RouterOS SSH Authentication Bypass Exploit
PoC: gha-lab-8aba6b05dc
Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of CloudPirates-io/helm-charts @ 9f5a7186
PoC: CVE-2026-42031-SQL-Injection-Scanner
CVE-2026-42031 SQL Injection Scanner for CKAN DataStore
PoC: gha-lab-5511dc3f73
Authorized security-research lab reproducing CVE-2026-45131 (pwn request in .github/workflows/pull-request.yaml) — snapshot of CloudPirates-io/helm-charts @ 9f5a7186
PoC: ai-tool-poisoning-guard
Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03, CVE-2025-54136).
PoC: gha-lab-733c168b88
Authorized security-research lab reproducing CVE-2026-44246 (GHSA-63mx-j37w-gh59): prompt injection via verbatim issue title/body inlining into the claude-code-action triage agent in nnU-Net's issue-triage workflow. Snapshot of MIC-DKFZ/nnUNet @ 9a1db0dd1c74894fa17e79014be4097f546a51be.
PoC: CVE-2021-1675
Simulated PoC — PrintNightmare Windows Print Spooler RCE/LPE (CVE-2021-1675 + CVE-2021-34527). Non-functional payload for detection engineering. CISA KEV · Patched July 2021 · MITRE T1068.
PoC: CVE-2025-31324
PoC — SAP NetWeaver Visual Composer unauthenticated file upload (CVSS 10.0). Benign JSP payload. CISA KEV May 2025 · Patched April/May 2025 · T1190 ·
PoC: gha-lab-677752506e
Authorized security-research lab reproducing CVE-2026-42298 (pull_request_target docker-build RCE in pr-docker-build.yml) — flattened snapshot of gitroomhq/postiz-app
PoC: CVE-2026-42559
Docker lab + Python PoC for CVE-2026-42559 - DNS rebinding via unvalidated Host header in the rmcp (Rust MCP SDK) Streamable HTTP server transport
PoC: CVE-2024-7804
Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)
PoC: gha-lab-456dd8a245
Security-research lab reproducing CVE-2026-41414 (pull_request_target pwn in .github/workflows/pr.yml) — snapshot of skim-rs/skim @ ca986f4, not a fork.
PoC: gha-lab-5bce203f66
Security-research lab: reproduction of CVE-2026-41249 (GHSA-q58j-g3f4-h26h) — pull_request_target pwn request in .github/workflows/static.yml, snapshot of coreshop/CoreShop@cc1e3f54
PoC: CVE-2025-57819
CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)
PoC: gha-lab-360f77d0d4
Authorized security-research lab: reproduction of CVE-2026-39866 (GHSA-9prc-pp2c-3427) — workflow_dispatch input template injection in .github/workflows/release_update.yml of LawnchairLauncher/lawnchair @ b089bae8c007f36a8ce0346725182a107d97cd05. Snapshot pinned to the vulnerable commit; owner-gated sign-info step retargeted for the lab.
PoC: CVE-2026-44578-next-js-ssrf
este laboratorio puede estar bien o mal esta el pruebas pero debe funcionar preguntale a la IA hahah
PoC: log4shell-exploitation-lab
CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation
PoC: CVE-2026-67276
CVE-2026-67276 - Draft or TODO
PoC: GitLab-CVE-2023-7028
A mock app for the GitLab CVE-2023-7028, which allow multile email adresses when ordering a password reset.
PoC: CVE-2026-64849-poc-lab
este laboratorio puede estar bien o mal preguntale a la IA estoy probando pero debe funcionar hahahah
PoC: CVE-2021-3030
Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx
PoC: CVE-2026-27876
Grafana SQL Expressions Arbitrary File Write to RCE
PoC: CVE-2026-28956-jxl-messages-surface
JPEG XL auto-decodes in the iOS Messages preview path — delivery-surface finding for CVE-2026-28956 (AppleJPEGXL), with patch-diff attribution (libjxl 0.10.4->0.10.5) and an honest reliability check on the public PoC.
PoC: CVE-2026-73570
Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)
PoC: CVE-2020-10770-keycloak-exploit-poc
Keycloak Blind SSRF POC
PoC: CVE-2026-1529-Keycloak-Exploit-Tool
Keycloak: Unauthorized organization registration via improper invitation token validation
PoC: CVE-2026-18963-keycloak
CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover
PoC: CVE-2026-64747
Root cause + macOS reachability PoC for CVE-2026-64747 (AppleAVE2 kext buffer overflow, fixed 26.6 / 905.40.1). Fully reversed AppleAVE2UserClient wire protocol, mode-5 LRB overflow math, IOKit PoC driving the configure path.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free