
CVE-2023-37250-POC
Proof-of-concept exploit for CVE-2023-37250, a local privilege escalation vulnerability in Windows, with a detailed write-up explaining the roaming…

Proof-of-concept exploit for CVE-2023-37250, a local privilege escalation vulnerability in Windows, with a detailed write-up explaining the roaming…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Exploit for CVE-2024-21345 providing kernel-level privilege escalation to gain root access on affected systems.

Exploit for CVE-2023-38646 in Metabase, achieving remote code execution and privilege escalation to root via unshare and setuid techniques.

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Detailed technical analysis and proof-of-concept exploit for CVE-2024-30051, a heap-based buffer overflow in the Windows DWM Core Library enabling…

This is working POC of CVE-2022-36271

Proof-of-concept exploit for CVE-2025-69604, demonstrating privilege escalation via malicious package installation in SuperDuper backup tasks on…

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

This is just a quick note on how to exploit these vulnerabilities to get root.

Escape from Docker using CVE-2017-1000112 and CVE-2017-18344, including gaining root privilage, get all capbilities, namespace recovery, filesystem…

Use RedxploitHQ to create a new Admin user into redwoodhq and get all the functions on the framework