
CVE-2026-67206
PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Automated WSUS MITM tool that spoofs Windows Update traffic over ARP, serves a signed executable with PowerShell payload, and escalates to local…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Exploit PoC for CVE-2026-64638 demonstrating WordPress pre-auth XSS to RCE. Captures an admin Application Password, publishes a page, uploads a…

Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Multi-vector exploit framework for CVE-2026-60206 targeting Oracle WebLogic Server SAML authentication bypass, with mass scanning, safe detection,…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Python exploit for CVE-2025-6254, an unauthenticated privilege escalation in Doctreat Core WordPress plugin, allowing admin account creation and full…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

Graph-based tool that maps hidden relationships and attack paths in Active Directory environments to identify and quantify privilege escalation…

Automated exploitation of CVE-2022-26923 (Certifried) for privilege escalation via AD CS abuse, RBCD, and Kerberos ticket extraction to dump NTLM…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Permanently disable EDRs as local admin