
CVE-2026-1357
Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

Grafana SQL Expressions Arbitrary File Write to RCE

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…

Unauthenticated SQL injection exploit for GLPI versions before 10.0.18, enabling database enumeration, credential extraction, and API token…

A critical zero-auth RCE vulnerability in SharePoint (CVE-2025-53770), now exploited in the wild, building directly on the spoofing flaw…

Python exploit and detection script for CVE-2024-27348, a remote code execution vulnerability in Apache HugeGraph Server via the Gremlin traversal…

Detecion for the vulnerability CVE-2017-15944

A selection of rebuilt and from scratch exploits, scripts and ideas that can be used in red-teaming scenarios.

Exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to RCE in Breeze Cache WordPress plugin. Includes lab setup, usage, and…

PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

Exploit code for CVE-2026-8451 targeting Citrix Netscaler, providing proof-of-concept for the vulnerability.

PoC exploit for unauthenticated remote code execution in DBGate via the /runners/start endpoint, with blind RCE mode and container-based testing…

An Vulnerability detection and Exploitation tool for CVE-2024-4358

Exploit for CVE-2021-21972 targeting VMware vCenter Server, enabling remote code execution via the vSphere Client.

AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…