
cve_2026_31431_audit
A security auditing toolkit for CVE-2026-31431 vulnerability research

A security auditing toolkit for CVE-2026-31431 vulnerability research

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Script Bash -- CVE-2021-3560

psexecsvc - a python implementation of PSExec's native service implementation

A proof-of-concept for CVE-2026-39987

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability

A script to automate privilege escalation with CVE-2023-22809 vulnerability

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

A easy sudo poc by cryingn.

Proof-of-concept exploit for CVE-2022-1257 that extracts and decrypts stored credentials from the McAfee Agent database (ma.db) using PowerShell.

Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp…

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.