
CIFSwitch
Proof-of-concept exploit for CVE-2026-46243, leveraging a fake NSS library and namespace manipulation to escalate privileges via cifs.upcall.

Proof-of-concept exploit for CVE-2026-46243, leveraging a fake NSS library and namespace manipulation to escalate privileges via cifs.upcall.

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

Cobalt Strike AggressorScripts CVE-2020-0796

all 4.4 ubuntu aws instances are vulnerable

A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc

Proof-of-concept exploit for CVE-2016-0051 (MS16-016) achieving local privilege escalation to SYSTEM on Windows 7, with compiled binaries and…

PoCs and technical analysis for three Cisco AnyConnect Windows vulnerabilities: local privilege escalation (CVE-2020-3433), denial of service…

Exploits for the win32kfull!bFill vulnerability on Win10 x64 RS2 using Bitmap or Palette techniques

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Exploit for CVE-2021-40449

CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation

CommonsBeanutils1,CommonsCollectionsK1

CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)

Proof-of-concept for CVE-2026-21508, demonstrating a DLL hijacking attack on Windows 11 that escalates privileges by loading a crafted DLL into…

CVE-2020-1048 bypass: binary planting PoC

0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

CVE-2017-5005 for Quick Heal Antivirus