
metasploit-framework
app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

Kernel-mode syscall wrapper with Zydis-based dynamic pattern finding for Windows 10/11

Race-condition exploit for Windows Defender vulnerability that escalates privileges to SYSTEM shell. Tested on Windows 10 and 11, with potential…

Windows Defender 0day proof-of-concept demonstrating a patch bypass for CVE-2026-69414, targeting Windows 11 25H2 and Server 2025 to evade endpoint…

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

CTT-PAN-OS-Exploit – CVE-2024-3400 (CVSS 10.0) with Convergent Time Theory enhancement. Uses α = 0.0302011 temporal dispersion, 33-layer phase…

Educational lab documenting step-by-step exploitation of CVE-2025-5548 (Stack Buffer Overflow) on Windows 11, from fuzzing and crash analysis to…

Windows privilege escalation exploit for CVE-2023-41772 (UIFuckUp) that elevates non-admin users to SYSTEM on Windows 10 (1809+) and 11 via a crafted…

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

Fork of https://github.com/hakaioffsec/CVE-2024-21338

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity processes) to read and write to…

CVE-2025-21293 is an elevation of privilege vulnerability in Active Directory Domain Services. It allows "Network Configuration Operators" to execute…

Proof-of-concept exploit for CVE-2023-23397, a Microsoft Outlook privilege escalation vulnerability. Sends a crafted email with a malicious UNC path…

Proof-of-concept exploit for CVE-2019-1221 targeting Internet Explorer 11 32-bit on Windows 10 x64 up to RS5, using VBScript.Encode and CVE-2019-0768…