
CVE-2021-43258
ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

Race-condition exploit for Windows Defender vulnerability that escalates privileges to SYSTEM shell. Tested on Windows 10 and 11, with potential…

CTT-PAN-OS-Exploit – CVE-2024-3400 (CVSS 10.0) with Convergent Time Theory enhancement. Uses α = 0.0302011 temporal dispersion, 33-layer phase…

Educational lab documenting step-by-step exploitation of CVE-2025-5548 (Stack Buffer Overflow) on Windows 11, from fuzzing and crash analysis to…

Windows privilege escalation exploit for CVE-2023-41772 (UIFuckUp) that elevates non-admin users to SYSTEM on Windows 10 (1809+) and 11 via a crafted…

CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1

Fork of https://github.com/hakaioffsec/CVE-2024-21338

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

CVE-2025-21293 is an elevation of privilege vulnerability in Active Directory Domain Services. It allows "Network Configuration Operators" to execute…

Proof-of-concept exploit for CVE-2023-23397, a Microsoft Outlook privilege escalation vulnerability. Sends a crafted email with a malicious UNC path…

Exploit for CVE-2019-0222 targeting Apache ActiveMQ 5.15.8, enabling remote code execution via crafted HTTP requests to the message broker's REST API.

Exploit for CVE-2020-11998 targeting Apache ActiveMQ 5.15.12, enabling remote code execution via crafted messages to the vulnerable message broker.

Exploit for CVE-2014-3576 targeting Apache ActiveMQ 5.10.1, enabling remote code execution via crafted serialized objects in the message broker.

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file…

Local privilege escalation PoC for CVE-2026-24294, abusing SMB arbitrary port and NTLM reflection to achieve SYSTEM on Windows Server 2025.

Proof-of-concept exploit for CVE-2019-0752 targeting Internet Explorer 11 on Windows 10 x64. Uses JavaScript DOM manipulation and special address…

Crashes any macOS High Sierra or iOS 11 device that is on the same WiFi network