The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These endpoints do not validate the tenant (store account) of the authenticated session against the ownership of the requested OrderForm.
CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)
Proof of concept for CVE-2026-36027 and CVE-2026-36028
This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an authenticated attacker to upload a malicious module via the module update functionality, leading to arbitrary file upload and remote code execution (RCE).
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
SimpleHelp OIDC Authentication Bypass PoC
DESIGN AND IMPLEMENTATION OF A VULNERABILITY SCANNER FOR CVE-2026-45498 IN MICROSOFT DEFENDER
High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break out of the sandbox along with full root privileges on user PC. I have been investigating about this vulnerability and has a lightweight script that runs in the terminal to check if you are vulnerable.
Python POC, Exploit for CVE-2026-33017
A modified version of the Rapid7 Metasploit module for CVE-2021-27877 that supports direct command execution for reliable vulnerability validation. Includes documentation explaining the exploit workflow, the module modifications, and usage examples.
My take on unlocking Xperia 5 SO-01M for p42 bootloader using CVE-2021-1931
Proof-of-concept exploit and lab environment for CVE-2026-25194
CVE-2026-30784: RustDesk hbbs Traffic Amplification PoC & PCAP Analysis
Gogs has Path Traversal in organization name that results in RCE through Git hooks
Crawl4AI <= 0.8.6 pre-auth RCE via AST sandbox escape (gi_frame.f_back.f_builtins chain) — CVSS 10.0
CVE-2025-69212 Proof-of-concept.
🛡️ CVE Proof-of-Concept Hub — 21 security advisories · 80+ vulnerabilities · 19 CVEs under review · 1 PUBLISHED (CVE-2026-66412)
OpenSTAManager RCE Exploit (CVE-2026-38751)
CVE-2025-69212 - OpenSTAManager OS Command Injection PoC