Python POC, Exploit for CVE-2026-29000
Tracking CIFSwitch (CVE-2026-46243), the CIFS cifs.spnego key-origin privilege escalation
CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.
Oracle REST Data Services (ORDS) Unauthenticated RCE (CVE-2026-46840)
Notepad++ 8.9.6 - Arbitrary Code Execution
YAMCS yamcs-core 5.12.7 - No Rate Limiting
YAMCS yamcs-core 5.12.7 - User Enumeration
YAMCS yamcs-core 5.12.7 - LDAP Injection
An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters without RFC 4515 escaping, allowing authentication bypass.
# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API
YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any account. Never returns HTTP 429. Fixed in 5.12.7.
Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257
Security advisories / CVE references for osTicket 1.18.3 (CVE-2026-38444, 38446, 38447)
This script safely checks the local version of the LiteSpeed cPanel plugin to determine if the system is running a version vulnerable to CVE-2026-48172. It does not send exploits or interact with network endpoints maliciously.
Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with screenshots.
A Marp slide deck about CVE-2025-53770
Linux Kernel - Local Privilege Escalation
Prodigy Commerce 3.3.0 - Local File Inclusion