
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

A list of awesome penetration testing tools and resources.

A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Gorsair gives root access on remote docker containers that expose their APIs

Post-exploitation tool for hiding processes from monitoring applications

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

Termux Privilege Escalation Tool & Root Manager - CVE-2026-43501

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

Automatic UAC-Bypassing for custom payloads during privilege escalation testing

Kernel-level security engine using eBPF-LSM to enforce file access policies based on process lineage, protecting sensitive data from supply-chain…

Universal Android root tool based on CVE-2016-5195. Watch this space.

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.