
Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Cloud-native C2 framework using cloud storage as dead-drop communication channel

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Source Code Management Attack Toolkit

Remote operations commands implemented using Beacon Object Files

A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

.NET post-exploitation toolkit for Active Directory reconnaissance and exploitation

MakeMeEnterpriseAdmin

Local & remote Windows DLL Proxying

encrypted-linux-kernel-modules

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

Exploit CVE-2024-43468 and CVE-2025-59213 to implant a controlled backdoor into SCCM Management Point's SQL stored procedure, enabling remote SQL…