
CVE-2025-13390
WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

One-click root kit for vivo iQOO Neo9S Pro (MT6989) exploiting CVE-2026-43499 futex PI UAF via MCAST transport, with scripts and analysis docs.

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Exploit kit targeting MikroTik RouterOS 6.49.18 with seven exploit scripts and support for CVE-2023-30799, featuring an Arabic interface and detailed…

Android kernel exploit research package for CVE-2026-43499, containing popsicle exploit source, embedded su payload, root bridge helper, and…