
vcenter_saml_login
A tool to extract the IdP cert from vCenter backups and log in as Administrator

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Stored XSS in Nagios Log Server 2024R1.3.1

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Proof of Concept exploits for CVE-2025-34322 and CVE-2025-34323 in Nagios Log Server

Proof-of-concept exploit for CVE-2025-27591, a local privilege escalation in the 'below' system monitor. Demonstrates symlink attack on log file to…

SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including…

Bypass age verification service from redhat

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…

Exploit the dirtycow vulnerability to login as root

Proof-of-concept exploit for CVE-2022-37969, a Windows Common Log File System driver local privilege escalation. Demonstrates heap spray, token…

Linux privilege escalation auditing tool that automates system enumeration, kernel vulnerability checks, password collection, log analysis, and cron…

Parses and resolves a single Active Directory principal's DACL to identify inbound access privileges, resolve SIDs, and log LDAP attributes for…

Technical analysis and proof-of-concept exploit for CVE-2023-28252, a Windows Common Log File System (CLFS) driver privilege escalation vulnerability…

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

iQOO Neo8 (PD2301, 5.10.246 GKI) CVE-2026-43499 GhostLock 适配 · 48 宏 target.h + offsets.json + 15 轮实测 log · 只缺 write layer

PoC exploit for Below privilege escalation (CVE-2025-27591) allowing local root access via symlink manipulation in world-writable log directory.