
CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE
Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

Open-Source Remote Administration Tool For Windows C# (RAT)

Six Degrees of Domain Admin

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

For when you want a computer to be done - without admin!

C# post-exploitation tool for abusing Microsoft Configuration Manager (SCCM) to perform lateral movement, credential gathering, and NTLM…

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Escalate from Backup Operator to Domain Admin using four techniques: remote service creation, DSRM registry manipulation, SAM/SYSTEM hive dumping,…

Permanently disable EDRs as local admin

This C# tool sprays for admin access over the entire domain

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…