
CVE-2017-14263
Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

PoC for the CVE-2024 Litespeed Cache Privilege Escalation

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege…

PoC for CVE-2020-24028: privilege escalation via authenticated permission bypass in ForLogic Qualiex, allowing user creation and password changes.

PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

Toolkit for CVE-2025-55182, also known as React2Shell.

WP REST API FNS <= 1.0.0 - Privilege Escalation

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Educational CVE PoC for a TOCTOU file-permission race in Flask; uses symlink replacement during the check-open window to disclose sensitive files.

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.