
CVE-2026-63030
Python mass exploit and detector for the WordPress Core pre-auth RCE chain CVE-2026-63030 and CVE-2026-60137, chaining SQL injection into remote code…

Python mass exploit and detector for the WordPress Core pre-auth RCE chain CVE-2026-63030 and CVE-2026-60137, chaining SQL injection into remote code…

Comprehensive penetration testing write-up and exploit details for Hack The Box - Enigma machine, covering local enumeration, OliveTin CVE-2026-27626…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

DCOM in memory and fileless lateral movement techniques through .Net deserilization

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Indirect syscalls + DInvoke made simple.

An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer

Bypassing UAC with SSPI Datagram Contexts

Amsi Bypass payload that works on Windwos 11

A PoC for achieving persistence via push notifications on Windows

Proof-of-concept exploit for CVE-2020-0728 demonstrating local privilege escalation via Windows TrustedInstaller COM service abuse to bypass file…

Journey to Try Harder !!!