
Thunderstorm
Modular framework to exploit UPS devices

Modular framework to exploit UPS devices

Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1

Zimbra CVE-2022-27925 PoC

Use-After-Free in Netfilter nf_tables when processing batch requests CVE-2023-32233

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.

Linux Persistence Detection, Hunting and Artifact Collection script

CVE-2024-22274: Authenticated Remote Code Execution in VMware vCenter Server

the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated…

vRealize RCE + Privesc (CVE-2021-21975, CVE-2021-21983, CVE-0DAY-?????)


Kernel-mode process protection driver with user GUI

From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

New Found 0-days!

Demo project how to bypass the disable_functions security control of PHP on Linux

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

CVE-2025-20029: Command Injection in TMSH CLI in F5 BIG-IP

Metasploit modules in testing