
proxmark3
Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

PoCs and exploits for CVEs discovered by NebuSec.

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Local privilege escalation exploit targeting a Linux kernel io_uring AF_VSOCK reference-count bug, using page-cache manipulation to overwrite…

网络摄像头漏洞扫描工具 | Webcam vulnerability scanning tool

GhostLock (CVE-2026-43499) adaptation for non-Android Linux 6.x ARM64

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

[CVE-2024-26581] Vulnerability Checker for BGN Internal

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…