
CVE-2026-13610
Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

One-click Android kernel rooting tool exploiting CVE-2026-43499 to install KernelSU, with official, bundled, and custom .so payload sources.

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing


KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Manipulating and Abusing Windows Access Tokens.

RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows

Source Code Management Attack Toolkit

In-memory token vault BOF for Cobalt Strike

RunasCs - Csharp and open version of windows builtin runas.exe


🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

A list of awesome penetration testing tools and resources.

A windows token impersonation tool

Programmatically start WebClient from an unprivileged session to enable that juicy privesc.

Local privilege escalation via PetitPotam (Abusing impersonate privileges).