
CVE-2023-0386-go-poc
Go proof-of-concept for CVE-2023-0386, using FUSE and overlayfs to escalate an unprivileged user to root on vulnerable Linux systems.

Go proof-of-concept for CVE-2023-0386, using FUSE and overlayfs to escalate an unprivileged user to root on vulnerable Linux systems.

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

A tool that allows you to search for vulnerable android devices across the world and exploit them.

Powershell script for enumerating vulnerable DCOM Applications

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Local privilege escalation exploit for CVE-2021-44731 targeting snap-confine versions 2.54.2 and lower. Automatically detects vulnerable binaries and…

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving…

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…