
CVE-2026-19658
Python 3 checker and exploit helper for CVE-2026-19658, a WordPress Give Tributes PHP object injection flaw, with FOFA target discovery and legacy…

Python 3 checker and exploit helper for CVE-2026-19658, a WordPress Give Tributes PHP object injection flaw, with FOFA target discovery and legacy…

Proof-of-concept exploit for CVE-2026-76578 and CVE-2026-76560, chaining anonymous LDAP ADD with a 389-ds SELFDN bypass to gain FreeIPA domain admin…

Weaponized proof-of-concept for CVE-2026-0073, an Android adbd authentication bypass enabling zero-click remote root access via Wireless ADB, with…

CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using…

Proof-of-concept exploit for CVE-2023-5966, an arbitrary file upload vulnerability in EspoCRM 2.7.4 and earlier, enabling remote code execution via a…

polkit pkexec Local Privilege Vulnerability to Add custom commands

Crystal port of GodPotato to abuse SeImpersonatePrivilege with indirect syscalls, dynamic API resolution and compile-time string obfuscation. Run…

Enhances Burp Suite with tab management, customizable themes, keyboard shortcuts, title renaming, window position memory, and UI utilities for faster…

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

Source generator to add D/Invoke and indirect syscall methods to a C# project.

MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.


CVE-2026-0073-Android-ADBD-bypass-POC汉化版

Transparent proxy that decrypts SSL traffic and prints out IRC messages.

Zap Extension for collaboration in Faraday

Fix host header error in zaproxy

BYOVD hunter to help prioritize windows drivers worth manual analysis