
CVE-2026-75898
Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

Dynamically invoke arbitrary unmanaged code from managed code without PInvoke.

Dynamically invoke arbitrary unmanaged code

This cheatsheet maps common impacket workflows to their modern alternatives

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.


CVE-2025-54100(PowerShell 远程代码执行漏洞)

使用PowsrShell掃描CVE-2024-4577

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

simple application with a (unreachable!) CVE-2022-45688 vulnerability

This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin…

Arbitrary Function Call Exploit using the ThrottleStop driver

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

Remote code execution (RCE) through insecure deserialization