
CVE-2026-37748
Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

C# Reflective loader for unmanaged binaries.

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Lateral Movement Using DCOM and DLL Hijacking

DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely

Chrome V8 n-day exploits that I've written.

Palo Alto - CVE-2026-0300 exploit

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

SecurityTube Linux Assembly Expert x86 Exam

Local & remote Windows DLL Proxying

Penetration testing framework with AI-driven decision engine

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Python exploit for CVE-2026-46725, achieving unauthenticated remote code execution in TYPO3 ceselector extension via PHP object injection and Monolog…

Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una…

CVE-2025-55182-POC