
XSS2Shell-CVE-2026-64638
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

I'll submit the poc after blackhat


Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

Empire client application

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

Android Remote Administration Tool