
CVE-2026-24291
About 2026 Guide: Bypass User Account Control Prompts on Windows 11

About 2026 Guide: Bypass User Account Control Prompts on Windows 11

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

Windows KASLR bypass using prefetch side-channel

This is the tool to dump the LSASS process on modern Windows 11

Windows local privilege escalation exploit targeting CVE-2026-24291, with support for Windows 10/11 and Server 2016-2022 for authorized security…

PrintNotifyPotato

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2

GitLab 11.4.7 SSRF配合redis远程执行代码

Unauthenticated IPC Local Privilege Escalation to SYSTEM via Debauchee Barrier Daemon TCP Port 24801

Shellcodes for Windows >= 11 x64

PoC exploit for a CSRF vulnerability in Apache Roller v6.1.2 profile update endpoint. Includes HTML form exploit code to demonstrate unauthorized…