CVE-2026-20230 - Cisco Unified CM
CVE-2026-49975 HTTP/2 Stream Amplification — Docker PoC with Web Console
Exploit for Copy-Fail Vulnerability - Python3 Version
Safe read-only version checker + Sigma rule for Redis CVE-2026-23479 (authenticated use-after-free → RCE). Find exposed instances, patch left-of-boom. By DugganUSA.
CVE-2026-41940 is a critical authentication bypass vulnerability affecting cPanel and WHM. This repository is designed to demonstrate its Proof-Of-Concept
WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection
CVE-2026-5076 — ARMember Premium <= 7.3.1 Insecure Password Reset Mechanism → Full Admin Account Takeover | Proof of Concept
CVE-2026-50142 — Heap allocation vulnerability in libheif HEIF sequence parser
HTTP/2 Bomb PoC — CVE-2026-49975 (HPACK indexed reference bomb + flow-control stall)
Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis. Python 3 stdlib-only, no network calls.
Este repositorio contiene un Proof of Concept (POC) para CVE-2026-49975, también conocida como HTTP/2 Bomb, una vulnerabilidad de denegación de servicio (DoS) remoto que afecta a la mayoría de los servidores web principales en su configuración HTTP/2 predeterminada, incluyendo:
Bulk scanning + one-click vulnerability exploitation
Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit
Add go CVE-2026-43284 / CVE-2026-43500 (dirtyfrag) local privilege escalation exploit
go CVE-2026-31431 (CopyFail) local privilege escalation exploit
CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM
Palo Alto Networks PAN-OS contains an authentication bypass caused by flaws in the GlobalProtect portal and gateway, letting attackers establish unauthorized VPN connections, exploit requires network access to the portal or gateway.
A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305.