IoT Security research conducted during my internship at IIIT Allahabad, leading to CVE-2026-65893, CVE-2026-65894, and the CERT-In Vulnerability Note CIVN-2026-0380.
CVE-2026-53921 โ odhcpd Stack Overflow (CVSS 9.8) ๐ก๏ธ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (IA_NA/IA_PD) overflow with MIPS/ARM shellcode, ROP chains, SOCKS5 proxy, persistence, log wiping & mass scanning. Use Ethically, Stay Legal. ๐
A proof-of-concept script to exploit CVE-2026-16232, an authentication bypass via the SmartConsole login process using an application token.
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`
**CVE-2024-28987** is a critical vulnerability in SolarWinds Web Help Desk (WHD) that allows remote attackers to access sensitive ticket information using **hardcoded credentials**. This vulnerability has a **CVSS score of 9.1 (Critical)** and is actively being exploited in the wild.
Isolated regression and security-control lab for CVE-2026-59891 in @sigstore/oci
A PoC for CVE-2026-64725
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings โ 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
Tplink wr841 v10 rce exploit
Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]
Exploit code for CVE-2026-55040, it can create auth header for any validate account.
Perl Image::WebP library. Unofficial. CVE-2026-58586
CVE-2026-14856 TastyIgniter v4.3.0
IBM Langflow OSS 1.0.0 through 1.10.0 contains a remote code execution [RCE]
Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533
CVE-2026-27577 - Draft or Todo