
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a…

Local privilege escalation exploit for Linux kernel CVE-2026-43284 (Dirty Flag), providing root access on vulnerable systems.

Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python…

Proof of Concept CVE-2025-24990 (Agere Systems's driver)

Exploit for the PwnKit vulnerability, CVE-2021-4034, written in Go

Proof-of-concept exploit for CVE-2021-4034, a local privilege escalation in pkexec, allowing arbitrary payload execution with root privileges.

Proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation in polkit's pkexec, verified on Debian 10 and CentOS 7.

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

A collection of selenium tests that might aid it takeover of a selenium node



It's only hitting vulnerable path in termdd.sys!!! NOT DOS

Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…