
CVE-2026-38577
Proof-of-concept demonstrating hardcoded root credentials (admin/system) in Tenda HG21 XPON modem firmware, enabling unauthorized root access via…

Proof-of-concept demonstrating hardcoded root credentials (admin/system) in Tenda HG21 XPON modem firmware, enabling unauthorized root access via…

Offensive Research & Exploit Development. Vulnerability research, PoC development, and offensive tooling for financial infrastructure.

Cacti 1.2.22 unauthenticated command injection

Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)

Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection

Exploit for CVE-2026-21858, a critical unauthenticated content-type parsing flaw in n8n allowing arbitrary file read, credential theft, and remote…

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

This script exploits a vulnerability (XSS) in the TPLink WR840N router, using a field for injecting javascript code.

Path traversal exploit for Splunk Enterprise on Windows (CVE-2024-36991) — interactive file harvester

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

Red Team Toolkit - A curated list of tools that are commonly used in the field for Physical Security, Red Teaming, and Tactical Covert Entry.