
CVE-2026-20217
Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

一键枚举所有用户名以及写入SSH公钥

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

[PoC] Privilege escalation & code execution via LFI in PwnDoC

Security research project

CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

Nagios IM 2.6 remote code execution exploit: CSRF + SQLi + RCE + LPE --> remote root

Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847

ZoneMinder up to 1.36.12 Language privilege escalation (and RCE) - Poc Exploit

Password Manager Pro Exploit

Unauthenticated Privilege Escalation via Account Takeover

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution