
CVE-2026-48907
Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Insecure Temp File Reuse in extract_zipped_paths()

About 2026 Guide: Bypass User Account Control Prompts on Windows 11

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

Patcher utility that bypasses CryptoQuant premium tier restrictions to unlock advanced analytics and real-time data access, with a Python GUI for…

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulnerability (CVE-2026-41940) in…

Proof-of-concept demonstrating argument injection leading to OS command injection in the CAI framework's find_file utility, enabling arbitrary…

Local privilege escalation exploit for CVE-2025-27591, abusing insecure symlink handling in the below utility's logging to overwrite arbitrary files…

Python 3.10-compatible implementation of the CVE-2026-31431 exploit, providing a workaround for missing os.splice in older Python versions.

Automated RCE exploit for Joomla JCE (CVE-2026-48907) with interactive shell, batch command execution, file download, and proxy support for…

Post-exploitation utility that scans kernel/OS version and configuration to suggest applicable local privilege escalation exploits.

Linux ptrace-based process tracing and debugging utility for inspecting system calls, memory, and program execution flow.

AndroidDriveSignity is a Python utility designed to bypass driver signature verification in Android kernel(ARMv8.3), facilitating the loading of…

Placeholder repository referencing CVE-2026-43499; no source code, documentation, or security functionality is evidenced in the available metadata.

Red-team EDR evasion utility that terminates security services by abusing Process Explorer driver functionality to bypass PPL and ObRegisterCallbacks.

Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation…

A C# utility for interacting with SCOM