
CVE-2026-48907
CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vani…

ROP ROCKET is an advanced code-reuse attack framework, with extensive ROP chain generation capabilities, including for novel Windows Syscalls attack,…

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

Shellcode injection technique. Given as C++ header, standalone Rust program or library.

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

A POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote…

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

pinky - The PHP mini RAT (Remote Administration Tool)

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

A collection of my shellcode samples.