
CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

CS4238 Computer Security Practices

Some setup scripts for security research tools.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Polymorphic binary encoder for offensive security payloads. Encodes shellcode with LFSR-based feedback loop, garbage instruction injection, and…

evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Offensive Software Exploitation Course

This repo contains C/C++ snippets that can be handy in specific offensive scenarios.

exploitdb // The official Exploit-Database repository

Remote DLL Injection with Timer-based Shellcode Execution

Pure C exploit for CVE-2023-4911 (Looney Tunables) — x86_64 & aarch64 implementations. Multi-processing brute-forcing, dynamic calibration,…


Detection reverse shell and kill it before trying shell.

This is a custom ASCII AND/SUB Encoder developed during my preparation for the legacy OSCE/CTP course

An Interactive Binary Patching Plugin for IDA Pro