
XSS2Shell-CVE-2026-64638
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

Impersonate Logged In Accounts & Execute Commands

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

I'll submit the poc after blackhat

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

This tool demonstrates the application of fundamental physics discoveries to cybersecurity.

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server

Empire client application

A PoC Java Stager which can download, compile, and execute a Java file in memory.