
CVE-2022-34302
Demonstrates CVE-2022-34302, a Secure Boot bypass via the New Horizon Datasys signed bootloader whose built-in custom PE/COFF loader executes…

Demonstrates CVE-2022-34302, a Secure Boot bypass via the New Horizon Datasys signed bootloader whose built-in custom PE/COFF loader executes…

CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

Analyze and demonstrate the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software on gaming laptops, with automated…

CVE-2024-56145 SSTI to RCE - twig templates

Checks if a system is potentially vulnerable to CVE-2024-49113 (LDAP Nightmare) by testing RPC connectivity, LDAP ports, Netlogon service, and LDAP…

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本

Checks for CVE-2020-11651 and CVE-2020-11652

Tools to scanner & exploit cve-2023-35078

Automated exploit for Chamilo command injection vulnerability (CVE-2023-34960) with auto shell upload capability for penetration testing and…

Curated OSINT compilation on Log4Shell (CVE-2021-44228) covering detection methods, attack surface, mitigation steps, and indicators of compromise…

SnakeYAML-CVE-2022-1471-POC

Low-level hardware debugging and security assessment tool for ASPEED BMC AHB interfaces. Probes PCIe, LPC, and UART interfaces to read/write…

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

POC for CVE-2024-37843. Craft CMS time-based blind SQLi


PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…