
CVE-2024-22889-Plone-v6.0.9
Proof-of-concept exploit for CVE-2024-22889, an incorrect access control vulnerability in Plone CMS v6.0.9 allowing remote attackers to view and list…

Proof-of-concept exploit for CVE-2024-22889, an incorrect access control vulnerability in Plone CMS v6.0.9 allowing remote attackers to view and list…

Curated repository of exploits, proof-of-concept code, and vulnerability research presentations from the phoenhex team, focused on binary…

Files and tools for CVE-2021-26258

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64,…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Advisories, proof of concept files and exploits that have been made public by @pedrib.

Forge certificates for Active Directory authentication using stolen Certificate Authority private keys, enabling persistent domain access with forged…

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

🗜️ A packer for Windows x86 executable files written in C and Intel x86 Assembly. The new file after packing can obstruct reverse…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

RansomLord is a proof-of-concept Anti-Ransomware exploitation tool that automates the creation of PE files, used to compromise ransomware…

Proof-of-concept exploit for CVE-2023-21608, a Use-After-Free vulnerability in Adobe Acrobat Reader enabling remote code execution via crafted PDF…

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

Bypassing NTFS permissions to read any files as unprivileged user.