
CVE-2026-78006-POC
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Proof-of-concept exploit for CVE-2025-2563, demonstrating the vulnerability and providing reproduction steps for security researchers.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Modular penetration testing platform that enables you to write, test, and execute exploit code.

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

CVE-2022-42475 飞塔RCE漏洞 POC

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

Root access to the kernel can be achieved simply by patching the Boot partition for reflashing. This solution is based on a non-parallel extended…

CVE-2021-4034 PoC , polkit < 0.131

The patching of Android kernel and Android system

Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)

Standalone exploit for MS10-059 vulnerability in Windows Canonical Display Driver, enabling local privilege escalation.

Crowdstrike Falcon 0day Privilege Escalation Vulnerability

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Patching and hooking the Linux kernel with only a stripped Linux kernel image.