
BloodHound
Six Degrees of Domain Admin

Six Degrees of Domain Admin

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

Exploit for CVE-2020-1472 (Zerologon) that exploits a cryptographic flaw in Netlogon to escalate privileges to domain admin in Active Directory…

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

TP-Link Archer BE800 V1 — VPN Key Injection RCE

Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

just record for myself

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…