gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)
Interactive RCE exploitation tool for CVE-2025-55182 (React Server Components)
python code for CVE-2018-15473, using paramiko
Technical analysis of CVE-2025-55182 (React2Shell RCE vulnerability)
Check if your AI agent setup is vulnerable to CVE-2026-33579
CVE-2026-33701 Unsafe Deserialization in OpenTelemetry Java Agent RMI Instrumentation
Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)
Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027)
CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)
"Exploit optimizado para la enumeración de usuarios en OpenSSH < 7.7 (CVE-2018-15473). Reescrito para Python 3 con sistema de calibración anti-falsos positivos y ejecución multihilo en tiempo real."
CVE-2026-5027 - Langflow Path Traversal to Remote Code Execution (CVSS 8.8)
CVE-2026-5201: Heap-based buffer overflow in gdk-pixbuf JPEG loader (CWE-122, CVSS 7.5)
Technical analysis of a SharePoint ToolShell (CVE-2025-53770) exploitation attempt involving RCE, webshell deployment, and MachineKey extraction.
Go offensive-security research library — 15+ injection methods, AMSI/ETW/ntdll-unhook evasion, sleep mask, PE ops (sRDI/BOF/CLR hosting), Meterpreter C2, persistence, UAC bypass, CVE-2024-30088 LPE. MITRE ATT&CK mapped.