
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

A proof-of-concept for CVE-2026-39987

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

A easy sudo poc by cryingn.

A security auditing toolkit for CVE-2026-31431 vulnerability research

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

psexecsvc - a python implementation of PSExec's native service implementation

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Script Bash -- CVE-2021-3560

Proof-of-concept exploit for CVE-2022-1257 that extracts and decrypts stored credentials from the McAfee Agent database (ma.db) using PowerShell.

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

Privilege escaltion exploit script for Boardlight machine on HackTheBox. I had access as the Larissa user and ran this script from the /tmp…

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.