
cve_2026_31431_audit
A security auditing toolkit for CVE-2026-31431 vulnerability research

A security auditing toolkit for CVE-2026-31431 vulnerability research

Proof-of-concept demonstrating credential disclosure in GeoVision ASManager via memory dumping, enabling unauthorized access and system compromise.

UAC bypass for x64 Windows 7 - 11

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

MAL-015: Isolation Escape 2 in Ansible Tower

Go proof-of-concept for CVE-2023-0386, using FUSE and overlayfs to escalate an unprivileged user to root on vulnerable Linux systems.

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check,…

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.