
zyxel-social-login-bypass-cve-2026-8508
Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

CVE-2025-26264 - GeoVision GV-ASWeb with the version 6.1.2.0 or less, contains a Remote Code Execution (RCE) vulnerability within its Notification…


KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Local privilege escalation via PetitPotam (Abusing impersonate privileges).

Rusty Impersonate

POC BLH Magelang CSIRT 2026 by babyrootkid

Ask a TGS on behalf of another user without password

Lateral Movement Using DCOM and DLL Hijacking



DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely


Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.