
Zerologon-Attack-CVE-2020-1472-POC
Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

My take on the needrestart Python CVE-2024-48990

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

DLL Planting in the Corsair iCUE v.5.3.102 CVE-2023-38822


Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

ipfire 2.25 authenticated remote code execution

Proof-of-concept exploit for CVE-2026-31431, a Linux kernel privilege escalation, with x86_64, AArch64, and C payloads to obtain root on affected…

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

Ghost CMS Privilege Escalation PoC

CVE-2023-6246 glibc __vsyslog_internal() heap buffer overflow exploitation using Convergent Time Theory (α = 0.0302011). 33-layer temporal heap spray…

CVE-2024-26229 Beacon Object File version

Proof-of-concept exploit for CVE-2025-2304, a privilege escalation vulnerability in Camaleon CMS 2.9.0 via mass assignment on the password change…

A Go implementation of PinTheft (CVE-2026-43494)