
CVE-2026-75898
Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin…

PowerShell Script to automatically abuse the BadSuccessor vulnerability (CVE-2025-53779)

Automated Active Directory auditing and enumeration tool that generates detailed HTML audit reports with CSV/XLSX export, designed for security…

Arbitrary Function Call Exploit using the ThrottleStop driver

CVE-2025-54100(PowerShell 远程代码执行漏洞)

Remote code execution (RCE) through insecure deserialization

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

Proof of concept for CVE-2020-36708

simple application with a (unreachable!) CVE-2022-45688 vulnerability

PowerShell exploit for CVE-2021-1675 PrintNightmare that disables AMSI and creates a local administrator account on vulnerable Windows systems.

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…