
CVE-2026-54121-PoC-Exploit
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check…

RCE OpenSSH CVE-2024-6387 Check and Exploit

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3.

OS Command Injection in Health Check → Remote Code Execution

a realistic POC demonstrating the missing `hasOwnProperty` check in [email protected]

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Offensive Software Exploitation Course

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications


First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

CVE-2024-4367 & CVE-2024-34342 Proof of Concept


An application to test windows and linux shellcodes

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

Local privilege escalation exploit for macOS XNU kernel (CVE-2026-43724) that uses an out-of-bounds write in dyld shared-cache slide walk to gain a…