
etaHEN
PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

JavaScript payloads that weaponize XSS bugs into critical impact, enabling account takeover and admin creation on popular CMS platforms for pentest…

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

PoC exploit for FreePBX 16 chaining CVE-2025-57819 (unauthenticated stacked SQL injection) and CVE-2025-61678 (arbitrary file upload/path traversal)…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

Automated mass scanner for CVE-2026-3584, an unauthenticated RCE in WordPress Kali Forms. Executes a 4-phase pipeline: REST API enumeration, form…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

Proof-of-concept exploit for WordPress REST API time-based blind SQL injection (CVE-2026-63030, CVE-2026-60137) with full chain escalation to remote…

Pre-auth SQL injection to remote code execution exploit for WordPress REST API batch endpoint. Creates admin account and executes system commands via…

Proof-of-concept exploit for CVE-2026-63030 chaining REST API route confusion, SQL injection, oEmbed cache poisoning, and Customizer privilege…

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

PowerShell exploit for CVE-2021-1675 (PrintNightmare) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…