
CVE-2026-26119
Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

Exploits targeting vBulletin.


PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Datajack Proxy allows you to intercept TLS traffic in native x86 applications across platforms

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…

Google App Engine Flask C2 redirector

flask heroku C2 redirector template

CVE-2022-38532 - Local Privilege Escalation vulnerability in MSI Center Application

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

All Working Exploits

load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.


