
GraphQLmap
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Multi-language educational exploit implementations for CVE-2026-31431, a Linux kernel local privilege escalation via the algif_aead module, with a…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

HiddenSteps — a local-first personal workflow intelligence platform

A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

cups-root-file-read.sh | CVE-2012-5519

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

Proof-of-concept for a persistent XSS vulnerability in MyBB 1.8.33 User CP, allowing authenticated users to inject HTML via the email field, with…

CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

CVE-2017-8291 CTF with docker and examples

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed…

Modular Bash toolkit that hardens Debian/Ubuntu systems for CyberPatriot competitions, automating account, firewall, SSH, PAM, and service hardening…