
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

LSTAR - CobaltStrike Translated to EN

NextJS exploiter for CVE-2025-55182 and more.

Automates SQL injection in WordPress wp-automatic plugin to create a new administrator user, exploiting CVE-2024-27956 for direct database…

Exploit for CVE-2024-10793: stored XSS in WP Activity Log plugin. Includes a detection script and a shell-based exploit for unauthenticated attackers.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…


Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…

Dumping LSASS with a duplicated handle from custom LSA plugin

A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user