
CVE-2019-10068-PoC
Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads a web shell for remote command execution.

Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads a web shell for remote command execution.

Python-based crypter that obfuscates payloads to bypass antivirus and EDR, generating FUD stubs for red team operations.

A simple and efficent script to obfuscate python payloads to make it completely FUD

Complete RMGP (CVE-2026-43499) workspace + experiment-state handoff for SM-A376B/A376BXXU1AZB7

GhostLock CVE-2026-43499 port for Galaxy Z Fold 8 (h8q)

Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without…

Proof-of-concept exploit for CVE-2026-27475, an authenticated insecure deserialization vulnerability in SPIP 4.4.8 leading to remote code execution.

Proof-of-concept for CVE-2025-59528, demonstrating authenticated remote code execution in Flowise via mcpServerConfig injection, with reproducible…

GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE

vivo X200 设备端一键 root App(Shizuku 授权 shell 域执行,CVE-2026-43499)

Proof-of-concept exploit for CVE-2025-55182/66478, a React Server Components deserialization RCE, delivering a reverse shell via crafted multipart…

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

PoC and detection templates for pre-auth RCE and payment tampering in Balbooa Forms (Joomla), including Python exploit and Nuclei detection template.

KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

I know you are probably here from Hack the Box, if so, yes this one actually works.

IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.