
winrar-exploit
C++ implementation of CVE-2025-8088 WinRAR exploit using Alternate Data Streams to drop payloads into Windows Startup folder for persistence.

C++ implementation of CVE-2025-8088 WinRAR exploit using Alternate Data Streams to drop payloads into Windows Startup folder for persistence.

Demonstrates arbitrary file write and privilege escalation in Hasleo Backup Suite Free <= 4.9.4 via symbolic links, enabling attackers to overwrite…

PoC that triggers Windows WebClient startup through EFS RPC call chains and WNF messages, enabling red teams to explore unprivileged service-start…

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

Python virus that will make your pc paralyzed once it opened :D

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Python exploit script for CVE-2018-20250 that generates a malicious RAR archive to achieve code execution via WinRAR's ACE file extraction…

Proof-of-concept exploit for CVE-2018-20250, a remote code execution vulnerability in WinRAR's ACE file extraction, enabling arbitrary file write to…

Automated exploit script for CVE-2018-20250 (WinRAR ACE extraction code execution) that generates a malicious archive file embedding a payload into…

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

KERUI K259 5MP Wi-Fi (Tuya Smart Security Camera) contains a code execution vulnerability

PoC exploit for CVE-2025-59536, a high-severity code injection vulnerability in Claude Code's startup trust dialog, enabling remote exploitation of…

CVE-2021-42559: Command Injection via Configurations in MITRE Caldera

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

Unauthenticated Blind Command injection in the enable_user function of DroboAccess v 2.1