
CVE-2026-64824-PoC
CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

PoC exploit for FreePBX 16 chaining CVE-2025-57819 (unauthenticated stacked SQL injection) and CVE-2025-61678 (arbitrary file upload/path traversal)…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

Proof-of-concept exploit for WordPress REST API time-based blind SQL injection (CVE-2026-63030, CVE-2026-60137) with full chain escalation to remote…

Proof-of-concept exploit for CVE-2026-63030 chaining REST API route confusion, SQL injection, oEmbed cache poisoning, and Customizer privilege…

Unauthenticated WordPress RCE exploit chain chaining route confusion (CVE-2026-63030) with SQL injection (CVE-2026-60137) to create an admin account…

Pre-auth SQL injection to remote code execution exploit for WordPress REST API batch endpoint. Creates admin account and executes system commands via…

Python exploit for CVE-2026-55579, an unauthenticated RCE in Pheditor via hardcoded default credentials. Executes commands and uploads files through…

Proofpoint Email Gateway: Low level authenticated user to admin RCE

Proof-of-concept exploit for CVE-2025-57819, demonstrating unauthenticated SQL injection to remote code execution chain in FreePBX, including admin…

Automated exploit chain for unauthenticated arbitrary file read leading to admin token forgery and sandbox bypass RCE in n8n. Includes interactive…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…