
CVE-2026-87902
Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Using CVE-2021-40449 to manual map kernel mode driver

Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes

Get your data from the resource section manually, with no need for windows apis

Python codes of my blog.

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

A collection of selenium tests that might aid it takeover of a selenium node

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…

Malleable C2 profiles for Cobalt Strike

Exploit for CVE-2025-64512 to get a reverse shell.

LSTAR - CobaltStrike Translated to EN

CVE-2023–4220 Exploit

Tools for get offsets and adding patch for support i386