Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
π Bypass CVE-2025-55182 protections with this tool, enhancing security assessments and streamlining vulnerability testing against WAF configurations.
CVE-2026-2395: Tar race file collision
Unauthenticated vulnerability that may allow remote attackers to compromise confidentiality and integrity, potentially leading to full system compromise.
CVE-2026-22200: Arbitrary file read + CNEXT RCE in osTicket
React Router's createFileSessionStorage() in certain versions allows unsigned cookies to be manipulated, enabling file system access outside the session directory.
CVE-2025-55182 React Server Components Remote Code Execution Exploit Tool
The PoC of information disclosure in Microsoft Desktop Windows Management.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.
π Exploit the Android/Linux kernel using CVE-2025-38352 with Chronomaly, designed for vulnerable v5.10.x kernels without needing specific offsets.
CyberPanel v2.4.3 XSS Chain to RCE-CVE-2026-41472
Overview of a application that I reversed using the CVE-2015-2291 exploit from the Intel Ethernet Diagnostics Driver (iQVW32.sys) for memory manipulation used in hwid spoofing.
Proof of Concept for CVE-2026-23745: Arbitrary File Overwrite vulnerability in node-tar (versions < 7.5.3).
RSC Detect CVE 2025 55182
A stored CrossβSite Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized URLβencoded JavaScript. The payload is stored and later executed in usersβ browsers, lead unauthorized actions.
CVE-2025-61686ε€η°ηdockerfileδΈpoc