
CVE-2026-40179-PoC
Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Simulated Zigbee Light Link (ZLL) factory reset exploit for CVE-2026-21006, demonstrating unauthenticated TouchLink command injection that wipes…

This is the tool to dump the LSASS process on modern Windows 11

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

Poc for CVE-2025-7771 to modify PPL Protection

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin <= 2.4.37 is vulnerable to Privilege Escalation

Windows privilege escalation exploit abusing a TOCTOU in Code Integrity to bypass Protected Process Light, execute as WinTcb-Light, and dump…

Windows kernel driver that removes Process Protection (PP) and Process Protection Light (PPL).

https://medium.com/@mnqazi/cve-2023-4696-account-takeover-due-to-improper-handling-of-jwt-tokens-in-memos-v0-13-2-13104e1412f3

Cobalt Strike BOF that exploits a Windows Protected Process Light bypass to dump protected processes, enabling credential access from LSASS.

Execute PowerShell code at the antimalware-light protection level.

iTop < 2.7.6 - (Authenticated) Remote command execution

Proof-of-concept C exploit that runs a DLL with WinTcb-Light protection from userland, demonstrating a Windows privilege-escalation primitive and…

A front-end JavaScript toolkit for creating DNS rebinding attacks.