
patch_CVE-2023-22809
Automated Bash script to patch CVE-2023-22809 by installing the latest sudo version, mitigating a local privilege-escalation vulnerability on Linux…

Automated Bash script to patch CVE-2023-22809 by installing the latest sudo version, mitigating a local privilege-escalation vulnerability on Linux…

Automated exploit for CVE-2023-51409, an unauthenticated arbitrary file upload vulnerability in the AI Engine ChatGPT Chatbot WordPress plugin,…

Proof-of-concept exploit for CVE-2022-30190 (Follina). Generates malicious docx files and hosts a server to trigger remote code execution via…

CVE-2022-2414 POC

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

CVE-2022-37201 POC

Proof-of-concept for CVE-2023-51214: a stored XSS vulnerability in a PHP-based activity log web application allowing remote code execution via…

An automated PoC for CVE 2018-15133

Exploit for CVE-2021-4034 (PwnKit) that provides a root shell via polkit pkexec vulnerability. Includes source code and build instructions.

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection

Exploit for CVE-2021-4034, a polkit pkexec privilege escalation vulnerability, providing a root shell on vulnerable Linux systems.

CVE-2018-7600.

Reproducer for CVE-2019-5736, a RunC container escape vulnerability. Provides build scripts and a KVM-based lab to confirm the exploit against…

Go-based exploit for CVE-2023-38646 in Metabase, enabling remote code execution and reverse shell connection to an attacker-controlled host.

Proof-of-concept exploit for CVE-2015-7547, a glibc getaddrinfo() stack-based buffer overflow. Includes server and client components to trigger the…

Proof-of-concept exploit for CVE-2022-43571, demonstrating remote code execution in Splunk via crafted sparklines to justify security updates.

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.