
VulnHub-DC1-Writeup
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

This repository details CVE-2020-6650, a vulnerability I discovered within Eaton's UPS Companion. All users should upgrade to v1.06 immediately or…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Disclosure of CVE-2023-34853: a stack overflow vulnerability in Supermicro X12DPG-QR BIOS firmware allowing local privilege escalation to DXE Runtime…

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

Repository dedicated to CVE-2024-23774, an unquoted Windows service path vulnerability, providing information and potential exploitation details.

Multiple untrusted search path vulnerabilities in MicroStation 7.1 allow local users to gain privileges via a Trojan horse (1) mptools.dll, (2)…

Audits Linux kernel exposure to privilege escalation exploits and verifies kernel hardening security measures using heuristic analysis and…

Proof-of-concept exploit for CVE-2020-0728 demonstrating local privilege escalation via Windows TrustedInstaller COM service abuse to bypass file…

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

Proof-of-concept exploit for CVE-2023-29336, a Win32k elevation of privilege vulnerability enabling SYSTEM-level access on affected Windows systems.

Linux kernel exploit for CVE-2020-27786 using userfaultd race condition to trigger use-after-free, leak kernel addresses via msg_msg, and overwrite…

Proof-of-concept PowerShell exploit for CVE-2019-1315, a Windows Error Reporting Manager arbitrary file move elevation of privilege vulnerability,…

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

It is the details of CVE-2025-45466

Technical analysis and proof-of-concept for CVE-2022-22718, a Windows Print Spooler privilege escalation vulnerability, including details on its…