JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package
Security research tool for FortiWeb CVE-2025-64446 vulnerability. Automated exploitation framework with advanced logging, real-time metrics, proxy debugging, and professional reporting. Includes retry logic, multi-threading, and configurable settings. For authorized security testing only. CVSS 9.8 Critical.
Huawei P10 VTR-L29C432B151 CVE-2017-8890 exploit research and bootloader-unlock journey
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.
Tplink wr841 v10 rce exploit
CVE-2020-7882 - Draft or Todo
Gitea diffpatch RCE
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0
CVE-2026-59726 - Draft or Todo
PoC for CVE-2026-66066 in Ruby on Rails
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
PoC for CVE-2024-36104 — unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path traversal to ProgramExport
CVE-2026-43813: CloudAttestation enforceEnvironment bypass
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0