Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710
⚠️ DISCLAIMER: This tool is intended for authorized penetration testing and educational purposes only. Using this tool against systems without explicit written permission is illegal. The developers are not responsible for any misuse or damage caused.
Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol
Cisco Catalyst SD-WAN Peering Authentication Bypass
Linux Kernel - Local Privilege Escalation
Casdoor 3.54.1 - Arbitrary File Write via Path Traversal
MeiG Smart FORGE_SLT711 - OS Command Injection
Proof-of-concept for CVE-2026-43284 — 4-byte XFRM/ESP page-cache write primitive to patch a setuid binary (x86_64, user namespaces). Includes kernel preflight + SUID scan.
XWiki Platform - CVE-2026-33137 PoC - Unauthenticated XAR Import via REST /wikis/{wikiName}
Repository for studying the CVE-2026-42945 vulnerability in nginx < 1.30
The code for personally reproducing the corresponding vulnerability
PoC for CVE-2026-28990, an ImageIO bug patched in iOS/macOS 26.5
CVE-2026-42945 turns a 17-year-old NGINX rewrite bug into remote code execution — even with ASLR on, by chaining the heap overflow with live worker memory read through a common file-read flaw.
CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE
The code for personally reproducing the corresponding vulnerability