
XSS2Shell
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Exploitation and Post-Exploitation Multitool for Palo Alto PAN-OS Systems affected by vulnerabilities CVE-2024-0012 and CVE-2024-9474

EDR-Freeze is a tool that puts a process of EDR, AntiMalware into a coma state.

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

A security auditing toolkit for CVE-2026-31431 vulnerability research

Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving…

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE