
CVE-2025-25614
Proof-of-concept exploit for CVE-2025-25614, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to modify fellow…

Proof-of-concept exploit for CVE-2025-25614, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to modify fellow…

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing students to modify exam rules via the /exams/edit-rule…

PoC of CVE-2025-46203

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

Collection of Windows 11 exploit proof-of-concepts and vulnerability demonstrations for security research and penetration testing.

PowerShell proof-of-concept that bypasses Windows User Account Control (UAC) to elevate privileges, intended for authorized penetration testing and…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Python exploit for CVE-2026-49083 targeting privilege escalation in the LatePoint Calendar Booking WordPress plugin. Provides automated exploitation…

Local privilege escalation exploit targeting CVE-2026-45258, written in C for penetration testing and vulnerability validation on affected systems.

Shell script demonstrating exploitation of CVE-2019-14287, a sudo privilege escalation vulnerability, for educational and penetration testing…

Automated privilege escalation script exploiting misconfigured setuid/sgid binaries, sudo, cron, and LD_PRELOAD on Unix systems. Designed for CTF and…

A collection of awesome penetration testing resources and tools