MotionEye v0.43.1b4 OS Command Injection
CVE-2026-3442
CVE-2026-29000 - pac4j-jwt Authentication Bypass PoC
Basic Proof of Concept (Poc) Exploit for React RSC - CVE-2025-55182
Easy Grade Pro 4.1 file parsing bug used as an educational example to show how beginners can start vulnerability research through reverse engineering.
OpenSSH User Enumeration (CVE-2018-15473) Lab
CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful content.
PoC for CVE-2025-60787 - Authenticated RCE in motionEye for all versions up to 0.43.1b4 (included)
CVE-2025-8088 — Educational proof-of-concept for WinRAR path traversal vulnerability via NTFS Alternate Data Streams (ADS), CVSS 8.4 HIGH, exploited by RomCom APT (Storm-0978), with configurable traversal depth, auto-discovery of rar.exe, and interactive terminal interface
Professional PoC for CVE-2025-60787: Remote Code Execution in MotionEye (<= 0.43.1b4). This exploit demonstrates an OS Command Injection vulnerability through client-side validation bypass, allowing attackers to execute arbitrary commands via configuration files.
PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.
CVE-2026-20079 — Cisco FMC Authentication Bypass
pac4j-jwt JwtAuthenticator auth bypass (CVE-2026-29000) writeup and PoCs
Cisco FMC Authentication Bypass PoC
Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Includes vulnerability breakdown, affected versions, exploitation methodology, and mitigation guidance for research and educational purposes.
CVE-2025-55182-in-docker
PoC of CVE-2021-4034 (PwnKit) for personal training purposes.
Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)