
CVE-2026-68138
Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.
Tools for maintaining access, exploring, and expanding control within compromised systems and networks.

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

A security research archive documenting vulnerabilities, technical analysis, and PoC demonstrations.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

This is my simple implementation of an exploit for the PwnKit vulnerability.

Deep-dive analysis of Windows CLFS type confusion (CVE-2022-24481) with root-cause explanation, exploitation flow, kernel gadget details, and working…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

POC of CVE-2026-51031 for arbitrary local file read

a vulnerability affecting Android version 12 & 13

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…

Android kernel exploit for Samsung Galaxy S22 that gains kernel-domain root via CVE-2026-43499, with SELinux permissive, device-specific kallsyms,…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Non-weaponized CVE-2016-5195 (Dirty COW) analysis and validation harness with root-cause research, upstream patch review, and safe lab-only PoC for…

Kernel privilege escalation research archive for CVE-2026-43499 (GhostLock) on Honor Magic6 Pro, documenting exploitation analysis, reverse…