
CVE-2025-4796
Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

Exploit the dirtycow vulnerability to login as root

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to modify section details. Includes step-by-step…

An Interactive Binary Patching Plugin for IDA Pro


A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support…

WiFi Penetration Testing Guide

Bypass Authentication

Detailed disclosure of CVE-2025-22963, a CSRF vulnerability in Teedy <= v1.11 enabling account takeover via forced user information changes.

pz-frontend-manager < 1.0.6 - CSRF Profile Picture Exploit

Educational lab demonstrating CVE-2022-33891 exploitation and patch application for Apache Spark with ACL authentication, including PoC verification…

Hands-on lab to exploit Apache 2.4.49 path traversal (CVE-2021-41773) using Docker, Nmap scanning, and curl to retrieve a flag.

The first vulnerability with the CVE identifier CVE-2021-41773 is a path traversal flaw that exists in Apache HTTP Server 2.4.49.

Proof-of-concept exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE-2021-41773) with remote code execution and reverse shell…

Setting up POC for CVE-2021-26084