
cve-2017-5123
Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape,…

Exploit for Magnus Billing v7 that achieves root privileges by exploiting CVE-2023-30258, enabling unauthorized access and system compromise.

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

PoC for CVE-2021-32099

Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

Suite for reverse shell handling geared toward working within the native shell

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

CVE-2025-9074: Docker Desktop LPE via Docker Engine API wo/ AuthN in posix sh

Exploit for CVE-2025-49132 targeting Pterodactyl Panel, combining path traversal with PEAR command injection for unauthenticated remote code…

Proof-of-concept exploit for CVE-2019-6440 achieving SYSTEM privilege escalation on Zemana antimalware via man-in-the-middle update interception and…

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…

Proof-of-concept exploit for CVE-2025-25968, an improper access control vulnerability in DDSN Interactive cm3 Acora CMS v10.1.1. Enables…

Exploit code for CVE-2019-14287 and CVE-2014-6271, targeting sudo privilege escalation and Shellshock vulnerabilities.

Documented XSS exploit for ZKBio CVSecurity v.6.4.1 with WAF bypass, enabling privilege escalation from Template Editor to administrator via crafted…

Automated exploit for an authenticated IDOR vulnerability in FortiWeb 7.4.3, enabling privilege escalation and account takeover via a logical bug.