
wp2shell
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

PoC exploit collection for Nexus Repository Manager 3 vulnerabilities (CVE-2020-10199, CVE-2020-10204, CVE-2020-11444) enabling remote code execution…

WorldFirst (Public) Docker API Exploit - My security researches involving Docker and Openshift

WORK IN PROGRESS. RAT written in C++ using Win32 API

Curated repository of CVEs with PoCs, articles, and detailed descriptions for vulnerability research and exploitation.

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root

PoCs for CVE-2020-11108; an RCE and priv esc in Pi-hole

Authenticated exploit for Moodle 3.9 that escalates teacher privileges to manager role and achieves remote code execution via malicious plugin upload.

Proof-of-concept exploit for Pi-Hole AdminLTE command injection (CVE-2019-13051) enabling remote root access via email field injection and cron-based…

Security for the modern age of AI: defend against bad AI agents and malicious npm packages

Exploit codes for rconfig <= 3.9.4

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)

CVE-2026-43499 (IonStack/GhostLock) pure-C re-root POC for Samsung SM-T878U / gts7l (T878USQS8DXE1)