Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.
Every new exploit,
on the radar.
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live11105 results
An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Show 1 repositories
An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.
Show 1 repositories
CVE-2026-28775 SNMP RCE
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements: * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37 * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279
Show 2 repositories
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Show 1 repositories
Fetching description from NVD…
Show 1 repositories
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 .
Show 1 repositories
Fetching description from NVD…
Show 1 repositories
CVE-2026-94597
Fetching description from NVD…
Show 8 of 10 repositories
Device-bound CVE-2026-64560 adaptation for Xiaomi 15 dada OS4.0.0.8
OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address
Exploit of CVE-2026-64560 for kernelCTF, LTS-6.12.95
CVE-2026-64560 toolkit: Go single-binary toolchain + realme RMX5010 (A16, SM8750) target port
针对 OnePlus Ace6 设备的 cve-2026-64560 复现
Fetching description from NVD…
Show 4 repositories
Local Privilege Escalation Affecting Millions of Gaming Laptops
🔍 Identify and understand the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software, impacting many gaming laptops.
🔍 Explore the CVE-2025-68921 vulnerability in Nahimic, enabling local privilege escalation to `NT AUTHORITY\SYSTEM`.
Fetching description from NVD…
Show 8 of 26 repositories
A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.
One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.
React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.
React2Shell - CVE-2025-66478 RCE Exploit
CVE-2025-66478 Proof of Concept
🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 10…
My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)
Fetching description from NVD…
Show 8 of 19 repositories
CVE-2025-49844 (RediShell)
CVE-2025-49844 – Redis Lua Parser Use-After-Free
Proof-of-concept for CVE-2025-49844
🚨 Exploit the CVE-2025-49844 Redis Lua interpreter UAF vulnerability to execute arbitrary shellcode and gain persistent backdoor access.
CVE-2025-49844 POC
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
Fetching description from NVD…
Show 8 of 69 repositories
Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
Local Privilege Escalation to Root via Sudo chroot in Linux
Privilege escalation to root using sudo chroot, NO NEED for gcc installed.
CVE-2025-32463 Proof of concept
This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.
PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability
# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so
A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.
Fetching description from NVD…
Show 2 repositories
Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage and CVE-2012…
Arvore de Merkle do zero em C# e .NET 8: provas de pertencimento, esquemas Bitcoin e RFC 6962, e a CVE-2012-2459 demonstrada
Fetching description from NVD…
Show 1 repositories
Temporary Root Research on Poco M7 Plus (SM6375) via Qualcomm GBL Exploit (CVE-2026-24088) + GhostLock Kernel Analysis (CVE-2026-43499)
Fetching description from NVD…
Show 8 of 158 repositories
GhostLock One-Tap Execution App (CVE-2026-43499)
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
Jailbreak supported Google Pixel phones with CVE-2026-43499
GhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
KSuRoot 4.0.0 — 基于 CVE-2026-43499(GhostLock) 的一键 KernelSU 提权工具。多内核支持:6.1 / 6.6 / 6.12 三族各有专属基线,另有 50 档上游内核适配;多机型动态库内置:122 条厂商载荷(vivo/iQOO、小米、三星、Pixel 等)离线可用、按机…
CVE-2026-43499 PoC
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
Fetching description from NVD…
Show 3 repositories
Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped
Fetching description from NVD…
Show 8 of 456 repositories
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks
A public open sourced tool. Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any applicat…
An agent to hotpatch the log4j RCE from CVE-2021-44228.
Fetching description from NVD…
Show 8 repositories
CVE-2026-64561
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing
Generic kernel live patch for the KVM/x86 shadow-MMU use-after-free (Zapscape, CVE-2026-64561)
Tracking Zapscape (CVE-2026-64561), the KVM/x86 shadow-MMU guest-to-host escape
Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
Linux 内核升级指南 - 修复 CVE-2026-64561
Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.
Show 8 of 12 repositories
Am I fixed? Was I hacked? Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778), CTX697174 (CVE-2026-88779) and CTX697191 (CVE-2026-107406, S…
Tooling related to CVE-2026-88771 and CVE-2026-88772
Defensive security checker for Citrix NetScaler ADC & Gateway — CVE-2026-88771 through CVE-2026-88778
Improper Input Validation (CWE-20) SSVC Scores Exploitation: Active Technical Impact: Total
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.
A detection/hunting script for compromise related to CVE-2026-88771
Fetching description from NVD…
Show 1 repositories
Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis
Fetching description from NVD…
Show 5 repositories
Windows privilege escalation using RegPwn
Exploit Windows local privilege escalation on clients and servers using tested code for CVE-2026-24291 across multiple Windows versions
Brute Ratel C4 BOF of the CVE-2026-24291
About 2026 Guide: Bypass User Account Control Prompts on Windows 11
Fetching description from NVD…
Show 2 repositories
Technical PoC for CVE-2026-2472 (GCP-2026-011): Unauthenticated and Stored Cross-Site Scripting (XSS) in google-cloud-aiplatform _genai/_evals_visualization (V…
Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.
Fetching description from NVD…
Show 8 of 14 repositories
PoC for the "Windows Notepad RCE"
CVE-2026-20841
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol h…
Fetching description from NVD…
Show 8 of 13 repositories
out-of-bounds write in Fortinet FortiOS CVE-2024-21762 vulnerability
Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762
Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)
The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.
Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.
The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.
This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vul…
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.