
CVE-2026-46215-POC
Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

AI-guided CTF - Break into a real server with Claude Code as your trainer

Binary Exploitation and Reverse-Engineering (from assembly into C)

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

NØW is a word-based shellcode encoding and obfuscation tool that transforms raw shellcode bytes into natural-looking English prose.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

A Curated list of Security Resources for all connected things

An updated collection of resources targeting browser-exploitation.


OpenType font that disassembles Z80 instructions

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

Proof-of-concept for CVE-2026-4060: unauthenticated time-based blind SQL injection in Geo Mashup WordPress plugin via ORDER BY clause. Includes…

A collection of samples and material related to process injection

Step-by-step walkthrough of exploiting CVE-2025-53770 (ToolShell) in a LetsDefend lab, covering RCE, web shell deployment, and incident response…