A PoC for demonstrating CVE-2026-25604
FortiSandbox RCE Scanner — CVE-2026-39808
Threat hunting query for bluehammer CVE windows CVE-2026-33825
Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP fuzzer, absent XSS on Magento via server sanitization, and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25) via Nessus + Wireshark PCAP validation.
Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.
Multi-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability
Security research & exploitation analysis of CVE-2025-55182 (React) — CVSS + OWASP Top 10 mapping
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
Proof of Concept for CVE-2026-29000, a vulnerability in pac4j-jwt
This is a modified version of the original CVE-2024-30088 exploit, adapted to work in non-interactive environments (WinRM).
CVE-2026-37750 — School Management System 1.0 - Reflected XSS
Windows IKEv2 Double-Free RCE
Fork of jfrog/go-dbmigrate with pgx/v5 upgrade (CVE-2026-32286)
A sophisticated, cross-platform exploit generator for **CVE-2026-34621** – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads to sandbox escape and arbitrary code execution on Windows and macOS.
PoC for Unauthenticated RCE in FortiSandbox via CVE-2026-39808
Apache Tomcat EncryptInterceptor Bypass → Unauthenticated RCE (CVE-2026-34486)