
CVE-2025-31644
CVE-2025-31644: Command Injection in Appliance mode in F5 BIG-IP

CVE-2025-31644: Command Injection in Appliance mode in F5 BIG-IP

Linux/Android kernel driver for RTL8812AU/21AU and RTL8814AU chipsets with monitor mode and frame injection support for wireless security testing.

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two…

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…


A tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing…

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.


Proof-of-concept exploit for CVE-2025-27591, demonstrating a binary vulnerability and providing a buildable Go exploit for security testing.

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

PoC of the phishing through setting browser in the fullscreen mode

Walkthrough of the CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN from first malformed peering request to root on the management plane.

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing…

A Node.js package for BLE (Bluetooth Low Energy) security assessment using Man-in-the-Middle and other attacks

Reproducing Spyboy technique to terminate all EDR/XDR/AVs processes

POC code for CVE-2020-3153 - Cisco anyconnect path traversal vulnerability

A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing

See adversary, do adversary: Simple execution of commands for defensive tuning/research (now with more ELF on the shelf)