
cve-2025-57819-exploit
Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…

Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…

Local privilege escalation exploit for sudo 1.9.14-1.9.17 that abuses CVE-2025-32463 chroot handling, planting a malicious NSS library constructor to…

Proof-of-concept exploit for CVE-2024-27956 SQL injection in ValvePress Automatic plugin. Creates admin users in WordPress to achieve remote code…

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

exp of CVE-2022-0847

PowerShell exploit for CVE-2021-1675 (PrintNightmare) performing local privilege escalation via Print Spooler, with custom DLL payload injection and…

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

Rust POC for CVE-2018-1932X kernel driver vulnerabilities

An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka…

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).

Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS)

Ghost CMS Privilege Escalation PoC

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

Local privilege escalation exploit for CVE-2021-1732 targeting Windows 10 and Server versions, with PoC code and affected system enumeration.

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…