
cve-2016-6662
Exploit code for MySQL remote root code execution and privilege escalation (CVE-2016-6662), including Python and C implementations.

Exploit code for MySQL remote root code execution and privilege escalation (CVE-2016-6662), including Python and C implementations.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root

Impersonate Logged In Accounts & Execute Commands

The Shadow Attack Framework

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Rusty Impersonate

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

PowerSploit - A PowerShell Post-Exploitation Framework

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command

Go-based exploit for CVE-2021-43858 targeting MinIO privilege escalation vulnerability. Executes against a specified IP and port to demonstrate the…

Chat with hacker assistant

Acunetix 0day RCE

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

CVE-2020-0796-EXP

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386