
cve-2021-3864
Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar

Some scripts to abuse kerberos using Powershell

A step by step workshop to exploit various vulnerabilities in Node.js and Java applications

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

Using IPv6 to Bypass Security

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

jenkins CVE-2017-1000353 POC


Implementation of Max Kellermann's exploit for CVE-2022-0847

My n-day exploit for CVE-2019-18634 (local privilege escalation)

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Proof-of-concept exploit for CVE-2024-2961, leveraging iconv encoding flaws and PHP filter chains to read arbitrary files from vulnerable servers via…