
CVE-2021-4034
Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Local privilege escalation via TOCTOU race condition in PackageKit's.

Automated privilege escalation script exploiting misconfigured setuid/sgid binaries, sudo, cron, and LD_PRELOAD on Unix systems. Designed for CTF and…

Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched…

Unauthenticated RCE on cups-browsed (exploit and nuclei template)

Este es un código del exploit CVE-2022-46169, que recree utilizando Python3! Si por ahí estás haciendo una máquina de HTB, esto te puede ser útil...…

Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data…

Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798).

An exploit script for CVE-2022-28368 designed to make exploitation less annoying, made for a HTB machine


Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and…

Python PoC for CVE-2023-46818

A working POC found while doing a HTB challenge. Original: https://github.com/user0x1337/CVE-2022-39227

"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was…

Automated local privilege escalation exploit for CVE-2015-1328 targeting Ubuntu overlayfs, designed for CTF environments with a simple bash…

ubuntu new PrivEsc race condition vulnerability