
DLHell
Local & remote Windows DLL Proxying

Local & remote Windows DLL Proxying

macOS 10.13.3 (17D47) Safari Wasm Exploit


Weblogic CVE-2020-14645 UniversalExtractor JNDI injection getDatabaseMetaData()

Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2


CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)

CVE-2020-4464 / CVE-2020-4450

Configure your Pi Zero 2W to be a BadUSB

Serving payloads only to allowed processes using Windows projected file system feature

PoC for the ThemeBleed Windows 11 CVE-2023-38146 written in python using impacket. https://jnns.de/posts/cve-2023-38146-poc/

Python script for exploiting command injection in Open PLC Webserver v3

Proof-of-concept exploit for CVE-2021-23758, demonstrating deserialization vulnerability in AjaxPro via ObjectDataProvider gadget chain with…

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

CVE-2015-3073 PoC