
CVE-2023-22809-sudoedit-privesc
A script to automate privilege escalation with CVE-2023-22809 vulnerability

A script to automate privilege escalation with CVE-2023-22809 vulnerability

WallEscape vulnerability in util-linux

PoC and vulnerability report for CVE-2025-47827.

Windows绕过EDR实现DumpHash

A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)

CVE-2022-39959

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

CVE-2018-19537

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

GreatXML bitlocker bypass vulnerability

DCOM-based privilege escalation tool for Windows Server 2012-2022 and Windows 8-11, elevating users with ImpersonatePrivilege to NT AUTHORITY\SYSTEM…

Exploit for CVE-2021-40449 - Win32k Elevation of Privilege Vulnerability (LPE)

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

CVE-2018-4280: Mach port replacement vulnerability in launchd on iOS 11.2.6 leading to sandbox escape, privilege escalation, and codesigning bypass.

D(COM) V(ulnerability) S(canner) AKA Devious swiss army knife - Lateral movement using DCOM Objects