
By-Poloss..-..CVE-2026-11551-PoC
Unauthenticated Privilege Escalation via Account Takeover

Unauthenticated Privilege Escalation via Account Takeover

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Unauthenticated Privilege Escalation to Administrator via Role Form Field

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

exploit of CVE-2022-0847 which directly remove password of the root account

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32…

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

Python script for Kerberoasting with targeted ACL abuse: sets temporary SPNs on users without them, extracts Kerberos hashes, then removes the SPN.…

CVE-2024-28000 LiteSpeed Cache Privilege Escalation Scan&Exp

CVE-2023-6654 EXP

Leak of any user's NetNTLM hash. Fixed in KB5040434

WallEscape vulnerability in util-linux

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

CVE-2023-6875 exploit written for Xakep.Ru

Crack any Microsoft Windows users password without any privilege (Guest account included)

CVE-2023-30765 / ZDI-23-905 - Delta Electronics Infrasuite Device Master Privilege Escalation