
ghostlock-s26
GhostLock (CVE-2026-43499) app for the Galaxy S26 series

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

Go-based exploit for CVE-2018-6574 using a shared library (attack.so) to demonstrate remote code execution vulnerability.

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

OS Command Injection in Health Check → Remote Code Execution

Tools and Techniques for Red Team / Penetration Testing

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

MindsDB Path Traversal to RCE PoC

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

yet another sleep encryption thing. also used the default github repo name for this one.

Windows RCE exploit for CVE-2020-27955 targeting git-lfs, affecting GitHub Desktop, VS Code, and other Git clients via crafted .bat/powershell…

CVE-2023-23924 (Dompdf - RCE) PoC

Authenticated Remote Command Execution in Gitlab via GitHub import

Exploit for CVE-2020-1472 (Zerologon) that resets the domain controller account password, enabling DCSync, with restoration steps to revert changes.

Batch and PowerShell exploit for CVE-2020-27955, a Git-LFS remote code execution vulnerability affecting Git, GitHub Desktop, VS Code, and other…

RCE exploit for CVE-2020-27955 targeting Git LFS on Windows, with .bat and PowerShell payloads for testing Git, GitHub CLI, VS Code, and other tools.

Exploit for CVE-2020-27955, a Git LFS remote code execution vulnerability, with a .bat/powershell payload targeting Windows Git clients.