
CVE-2026-8181
Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…


PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

In-memory token vault BOF for Cobalt Strike


Silent;Call — Pre-authentication remote root on Cisco CUCM 15.x (CVSS 10.0)

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

A C# utility for interacting with SCOM

POC tool for ResetNightmare (CVE-2026-27912)


CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…


cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…