
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-
PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served…

Proof-of-concept exploit for CVE-2018-15133 that achieves remote command execution on Laravel applications by abusing insecure deserialization with…

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

POC for CVE-2026-21858

JavaScript-based exploit for Chrome V8 vulnerability CVE-2020-6468, with a d8 shell script and an HTML-based Chrome target.

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…