
glass-cage-i18-2025-24085-and-cve-2025-24201
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox…

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

CVE-2025-55182 & CVE-2025-66478 proof of concepts


A python script to dump files and folders remotely from a Windows SMB share.

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Reuse open handles to dynamically dump LSASS.

Bypassing NTFS permissions to read any files as unprivileged user.

A simple utility to convert EXE files to JPEG images and vice versa.

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

ActionScript Proof of Concept to perform cross-domain reads

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version…

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.