
CVE-2022-3172
Proof-of-concept exploit for CVE-2022-3172 in Kubernetes, demonstrating unauthorized access to metrics API via a crafted token.

Proof-of-concept exploit for CVE-2022-3172 in Kubernetes, demonstrating unauthorized access to metrics API via a crafted token.

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a…

This tool demonstrates CVE-2026-38194, a vulnerability in Teledyne Digital Imaging Sapera Memory Manager (v9.0.0.0 and below). The CORMEM.SYS kernel…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

Proof-of-concept exploit for CVE-2024-0132 enabling container escape via NVIDIA container toolkit, allowing host filesystem access and Docker daemon…

PowerShell local privilege escalation exploit for PrintNightmare (CVE-2021-34527) targeting Windows Print Spooler. Embeds custom DLL payload to add…

Proof-of-concept exploit for CVE-2024-2771, a privilege escalation vulnerability in the Fluent Forms WordPress plugin via an unauthenticated REST API…

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

Proof-of-concept exploit for CVE-2021-22911 targeting Rocket.Chat 3.12.1. Automates privilege escalation from low-privileged user to administrator…

Proof-of-concept for a stored XSS vulnerability (CVE-2021-44217) in Ericsson CodeChecker's comments component, enabling cookie theft and sensitive…

Rust PoC for a Linux kernel local privilege escalation vulnerability, exploiting the Crypto API and splice to overwrite page cache and modify…

Python proof-of-concept for CVE-2026-30944, exploiting a BOLA vulnerability in StudioCMS to escalate privileges via insecure API token generation.


Exchange your privileges for Domain Admin privs by abusing Exchange

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

Beacon Object File for Cobalt Strike that executes .NET assemblies in beacon with evasion techniques.

POC for CVE-2024-42327: Zabbix Privilege Escalation -> RCE