
CVE-2024-28000-Exploit-Lab
Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJ…

Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege…

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.


Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation

Proof-of-concept for CVE-2026-31282: Totara LMS login page access control bypass enabling unauthenticated brute-force credential attacks. Includes…

Detects vulnerable Cisco Meeting Server configurations (CVE-2018-15446) by enumerating active conference IDs and testing weak passcodes for…

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

An exploitation tool to extract passwords using CVE-2015-5995.