
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

NextJS exploiter for CVE-2025-55182 and more.

Automates SQL injection in WordPress wp-automatic plugin to create a new administrator user, exploiting CVE-2024-27956 for direct database…

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11

Exploit for CVE-2024-10793: stored XSS in WP Activity Log plugin. Includes a detection script and a shell-based exploit for unauthenticated attackers.

A firebeam plugin that exploits the CVE-2024-26229 vulnerability to perform elevation of privilege from a unprivileged user

LSTAR - CobaltStrike Translated to EN

Dumping LSASS with a duplicated handle from custom LSA plugin

Aggrokatz is an aggressor plugin extension for Cobalt Strike which enables pypykatz to interface with the beacons remotely and allows it to parse…
