
oscp-notes-2026
OSCP field notebook: merged technique vault and numbered notes. MIT.

OSCP field notebook: merged technique vault and numbered notes. MIT.

CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.

CVE-2023-24055 PoC (KeePass 2.5x)

WallEscape vulnerability in util-linux

Unauthenticated Privilege Escalation via Account Takeover

CVE-2023-30765 / ZDI-23-905 - Delta Electronics Infrasuite Device Master Privilege Escalation

Critical vulnerability in Siemens RuggedCom ROS devices allowing attackers to derive a hidden factory account password from the device MAC address…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

User Enumeration vulnerability in Kaiten (workflow management system)

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Mini-paper on CVE-2017-2751, HP EFI password extraction.

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+…