Flowise 3.1.3 - arbitrary code execution
Hydra - Stack Buffer Overflow
Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)
HTB "Abducted" write-up. Exploit CVE-2026-4480 (Samba RCE) → SMB wide links → systemd → root. Full methodology and flags.
AF_ALG/splice 기반 Linux Page Cache 변조 취약점 분석 및 대응 실습
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an empty X-Api-Key header value.
Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)
Proof of Concept (PoC) for CVE-2026-49975 – HTTP/2 server memory exhaustion attack leveraging HPACK amplification and connection retention (HTTP/2 Slowloris).
Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")
Joomla Extension 4.1.4 - PHP Object injection
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
Windows Defender (MsMpEng.exe) - Race Condition
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
KNX visualisering - Broken Access Control
Epson Printer RAW Protocol Exploit Framework
CVE-2026-54998 RCE Exploit
CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.