
LFISuite
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

Create local administrators in Windows using the SAMR API. In C#, Crystal, Python, Rust, Golang, Nim and Deno (Javascript)

Polkit D-Bus Authentication Bypass Exploit

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

WordPress CVE-2026-87902 LFI-to-RCE toolkit with a weaponized exploit chain (PEAR RCE, webshell, admin creation, loot) and a non-intrusive…

OfensivePipeline allows you to download and build C# tools, applying certain modifications in order to improve their evasion for Red Team exercises.

Pass the Hash to a named pipe for token Impersonation

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

Pass the Hash to a named pipe for token Impersonation

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

Multi-mode vulnerability scanner for Next.js RCE (CVE-2025-66478/55182) with safe side-channel detection, RCE proof-of-concept, WAF bypass…

Previously-0day exploit from the Hacking Team leak, written by Eugene Ching/Qavar.

This repository contains an exploit demonstration for CVE-2024-0670, a local privilege escalation vulnerability affecting the CheckMK Agent for…

Automates the compilation and serving of the PwnKit exploit for CVE-2021-4034, enabling local privilege escalation on vulnerable Linux systems.

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad RCE via markdown links. Generates crafted .md files to trigger remote payloads, app…

POC to replicate the full 'Follina' Office RCE vulnerability for testing purposes

CVE-2020-11107-Local-Privilege-Escalation-XAMPP-7.2.29-7.3.x-7.3.16-7.4.x-7.4.4