
CVE-2026-18366
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

Source Code Management Attack Toolkit

This is a pre-authenticated RCE exploit for VMware vRealize Operations Manager

Enumerate and attack Active Directory with LDAP session persistence, ACL abuse, Kerberoasting/ASREProasting, shadow credentials, RBCD, and NTLM relay.

Microsoft Signed PowerShell scripts

A care package of useful bofs for red team engagments

A Python based ingestor for BloodHound

New generation of wmiexec.py

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

A BOF to enumerate system process, their protection levels, and more.

My proof-of-concept exploits for the Linux kernel

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

Python script to efficiently find files on UNIX like file systems with specific properties (quicker than find)

Offline command line lookup utility for GTFOBins (https://github.com/GTFOBins/GTFOBins.github.io), LOLBAS (https://github.com/LOLBAS-Project/LOLBAS),…

iOS gamed exploit (fixed in 15.0.2)

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting