
CVE-2020-9496
Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

Local privilege escalation exploit for CVE-2023-36802 targeting Windows kernel streaming service (MSKSSRV) on Windows 11 22H2, using I/O Ring…

Ping Exfiltration Command and Control (PiX-C2)

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code execution via…

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

Wing FTP Server RCE via Lua Injection

Proof-of-concept exploit for CVE-2025-47812: unauthenticated remote code execution in Wing FTP Server <= 7.4.3 via NULL byte injection in the…

Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality,…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Malleable C2 profiles for Cobalt Strike

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

CVE-2019-12949

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…

Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion