Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Reproduced Vulnerabilities

Every card below is a CVE our Claude Code agent reproduced end-to-end: it reads the PoC, rebuilds the real vulnerable system in an isolated Docker sandbox, launches a real exploit, and records the whole run with asciinema. A "VULNERABLE:" line is hard proof the exploit fired.

42 vulnerabilities reproduced with live recordings
Full sandbox recordings + exploit POC are a Pro+ exclusive. Upgrade to Pro+ — limited ¥499/mo
CVE-2025-62521CriticalCVSS 10.0
ChurchCRM has unauthenticated RCE in its Install Wizard
Success marker:VULNERABLE: Unauthenticated RCE via setup wizard DB_PASSWORD injection. Proof: RCE_CONFIRMED_by_CVE-2025-62521
Pro+ — watch recording Unlock full PoC steps
CVE-2026-28229CriticalCVSS 9.8
Argo Workflows has unauthorized access to Argo Workflows Template
Pro+ — watch recording Unlock full PoC steps
CVE-2024-39914CriticalCVSS 9.8
FOG has a command injection in /fog/management/export.php?filename=
Success marker:VULNERABLE: uid=33(www-data) — OS command injection via filename param in /fog/management/export.php
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7538CriticalCVSS 9.8
Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection
Pro+ — watch recording Unlock full PoC steps
CVE-2026-42880CriticalCVSS 9.6
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Success marker:VULNERABLE: Extracted Kubernetes Secret via ArgoCD ServerSideDiff mechanism (CVE-2026-42880): password=S3cretP@ssw0rd!2024 username=admin
Pro+ — watch recording Unlock full PoC steps
CVE-2025-13607CriticalCVSS 9.4
D-Link CCTV camera model DCS-F5614-L1 Missing Authentication for Critical Function
Success marker:VULNERABLE: Unauthenticated credential leak via /cgi-bin/config.cgi - admin password D1nk@dmin2024! exposed without authentication
Pro+ — watch recording Unlock full PoC steps
CVE-2024-32880CriticalCVSS 9.1
pyLoad allows upload to arbitrary folder lead to RCE
Success marker:VULNERABLE: RCE confirmed via Jinja2 SSTI in /web/ endpoint - command executed as: uid=0(root) gid=0(root) groups=0(root)
Pro+ — watch recording Unlock full PoC steps
CVE-2024-42366CriticalCVSS 9.1
VR Overlay RCE
Success marker:VULNERABLE: XSS via unsanitized overlay notification image field led to RCE — /tmp/vrcx-rce-pwned created via CefSharp AppApiVr elevated binding
Pro+ — watch recording Unlock full PoC steps
CVE-2025-22146CriticalCVSS 9.1
Improper authentication on SAML SSO process allows user impersonation in sentry
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7675HighCVSS 8.8
Shenzhen Libituo Technology LBT-T300-HW1 apply.cgi start_lan buffer overflow
Success marker:VULNERABLE: Buffer overflow in apply.cgi start_lan via Channel parameter - process crashed (SIGSEGV/exit 139)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7674HighCVSS 8.8
Shenzhen Libituo Technology LBT-T300-HW1 Web Management start_single_service buffer overflow
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7548HighCVSS 8.8
Totolink NR1800X cstecgi.cgi sub_41A68C command injection
Success marker:VULNERABLE: uid=0(root) gid=0(root) groups=0(root) — command injection confirmed in setUssd handler
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7513HighCVSS 8.8
UTT HiPER 1200GW formRemoteControl strcpy buffer overflow
Success marker:VULNERABLE: strcpy buffer overflow in /goform/formRemoteControl - 1800 byte payload overflowed 256-byte buffer (CVE-2026-7513)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7512HighCVSS 8.8
UTT HiPER 1200GW formUser strcpy buffer overflow
Success marker:VULNERABLE: strcpy buffer overflow in /goform/formUser - 2000-byte Profile copied into 256-byte buffer without bounds check
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41490HighCVSS 8.3
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
Success marker:VULNERABLE: SQL injection via dynamic partition key - 3 rows returned instead of 1, partition keys are interpolated unsanitized into SQL WHERE clauses
Pro+ — watch recording Unlock full PoC steps
CVE-2024-32883HighCVSS 7.7
MCUboot Injection attack of unprotected TLV values
Success marker:VULNERABLE: BOOT_RECORD TLV (type 0x60) injected into unprotected TLV area accepted
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7670HighCVSS 7.3
Jinher OA UserSel.aspx sql injection
Success marker:VULNERABLE: SQL injection via DeptIDList in UserSel.aspx leaked admin password: SuperSecret123!
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7594HighCVSS 7.3
Flux159 mcp-game-asset-gen MCP index.ts image_to_3d_async path traversal
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7593HighCVSS 7.3
Sunwood-ai-labs command-executor-mcp-server MCP index.ts execute_command os command injection
Success marker:VULNERABLE: OS command injection confirmed - read /etc/shadow via "ls ; cat /etc/shadow" VULNERABLE: OS command injection confirmed - read /etc/shadow via "ls ; cat /etc/shadow"
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7579HighCVSS 7.3
AstrBotDevs AstrBot Dashboard auth.py hard-coded credentials
Success marker:VULNERABLE: Hard-coded credentials accepted - username=astrbot password=77b90590a8945a7d36c963981a307dc9 JWT_token=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ...
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7592HighCVSS 7.3
itsourcecode Courier Management System edit_staff.php sql injection
Success marker:VULNERABLE: SQL injection in edit_staff.php ID parameter exposed secret: s3cret_admin_p@ss
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7555HighCVSS 7.3
itsourcecode Electronic Judging System login.php sql injection
Success marker:VULNERABLE: SQL injection in login.php Username parameter - bypassed authentication, leaked DB version: 10.5.29-MariaDB-0+deb11u1
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7545HighCVSS 7.3
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
Success marker:VULNERABLE: SQL injection in checkEmail endpoint exposed secret: SCHOOL_SECRET_KEY_4BF2A9D8C1E7
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7506HighCVSS 7.3
SourceCodester Hotel Management System check sql injection
Success marker:VULNERABLE: SQL injection confirmed - extracted secret_data=FLAG{sql_injection_successful}, password=supersecretpassword123 from admin_users table via room_type parameter
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7413HighCVSS 7.2
Persistent undocumented backdoor access in Yarbo robot
Success marker:VULNERABLE: Root SSH access with hardcoded password hy@0886!# confirmed - uid=0(root) gid=0(root) groups=0(root)
Pro+ — watch recording Unlock full PoC steps
CVE-2026-7725MediumCVSS 6.3
PrefectHQ prefect GitRepository Pull storage.py argument injection
Success marker:VULNERABLE: uid=0(root) gid=0(root) groups=0(root) — RCE confirmed via git --upload-pack argument injection through commit_sha [trigger] Exploitation successful!
Pro+ — watch recording Unlock full PoC steps
CVE-2026-44500MediumCVSS 5.3
ZEBRA: Allocation Amplification in Inbound Network Deserializers
Pro+ — watch recording Unlock full PoC steps
CVE-2026-41417MediumCVSS 5.3
Netty vulnerable to HTTP request smuggling and RTSP request injection via DefaultHttpRequest.setUri()
Success marker:VULNERABLE: CRLF injection via DefaultHttpRequest.setUri() confirmed - HTTP request smuggling possible
Pro+ — watch recording Unlock full PoC steps
CVE-2026-2327MediumCVSS 5.3
Markdown-It 安全漏洞
Success marker:VULNERABLE: ReDoS confirmed via /\*+$/ regex in markdown-it linkify - vulnerable regex took 4948ms vs 0ms for fixed code (50000 * chars payload)
Pro+ — watch recording Unlock full PoC steps
CVE-2020-15104MediumCVSS 4.6
TLS Validation Vulnerability in Envoy
Success marker:VULNERABLE: Wildcard SAN *.test.local incorrectly matched nested subdomain deep.sub.test.local (CVE-2020-15104). Envoy allowed the TLS connection.
Pro+ — watch recording Unlock full PoC steps
CVE-2022-3171MediumCVSS 4.3
Memory handling vulnerability in ProtocolBuffers Java core and lite
Pro+ — watch recording Unlock full PoC steps
Lexar_F35 授权问题漏洞
Success marker:VULNERABLE: Auth bypass confirmed - accessed encryption_key=AES-256-KEY-a3f8b2c1d4e5f6071829 without valid password
Pro+ — watch recording Unlock full PoC steps
RabbitMQ Node can log Basic Auth header from an HTTP request
Success marker:VULNERABLE: Basic Auth username logged in HTTP access log: 127.0.0.1 - guest [31/May/2026:10:04:08 +0000] "GET /api/overview HTTP/1.1" 200 2647 "" "curl/8.5.0"
Pro+ — watch recording Unlock full PoC steps
uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
Success marker:VULNERABLE: v3 silently wrote 5 bytes into undersized 5-byte buffer (needs 16) without RangeError. Partial UUID data: [69, 161, 19, 172, 199]
Pro+ — watch recording Unlock full PoC steps
Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
Pro+ — watch recording Unlock full PoC steps
redis-server Lua use-after-free may allow remote code execution
Pro+ — watch recording Unlock full PoC steps
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
Pro+ — watch recording Unlock full PoC steps
Open-Vehicle-Monitoring-System-3 安全漏洞
Success marker:VULNERABLE: CANswitch DLC=196 overflows data.u8[8] buffer (memcpy 196 bytes into 8-byte buffer)
Pro+ — watch recording Unlock full PoC steps