
halo-cve-2026-67919
halo cms plugin 1-request rce from a url, PoC + exploit chain

halo cms plugin 1-request rce from a url, PoC + exploit chain

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack


NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

Quick python utility I wrote to turn HTTP requests from burp suite into Cobalt Strike Malleable C2 profiles

PowerSploit - A PowerShell Post-Exploitation Framework

Research code & papers from members of vx-underground.

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.


Tools and PoCs for Windows syscall investigation.

ShellcodeFluctuation PoC ported to Nim

More examples using the Impacket library designed for learning purposes.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…