
CVE-2026-5027
Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow leading to unauthenticated remote code execution via cron job…

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow leading to unauthenticated remote code execution via cron job…

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Python Script that will DoS a WP server that is utilizing WP-CRON

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

Sudo Baron Samedit Exploit

Proof-of-concept exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo enabling local privilege escalation to root.…

Proof-of-concept exploit for a command injection vulnerability in VitalPBX Task Manager module, demonstrating reverse shell payload delivery via cron…

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

Projeto educacional desenvolvido em Python com foco na análise da vulnerabilidade CVE-2021-3156 (Baron Samedit), uma falha crítica no sudo que…

Proof-of-concept exploit for CVE-2021-3156, a heap-based buffer overflow in sudo that allows local privilege escalation to root via sudoedit -s with…

Red Team exploitation of CVE-2021-3156 (Baron Samedit) – Heap Buffer Overflow in Sudo leading to Local Privilege Escalation on Ubuntu 20.04

CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

A Powershell client for dnscat2, an encrypted DNS command and control tool.