
CVE-2022-41082-POC
Post-authentication remote code execution exploit for Microsoft Exchange Server (CVE-2022-41082) with a PowerShell privilege escalation script for…

Post-authentication remote code execution exploit for Microsoft Exchange Server (CVE-2022-41082) with a PowerShell privilege escalation script for…

Linux kernel privilege escalation exploit for CVE-2023-32233 using nft_quota UAF, ROP chain, and modprobe_path overwrite to gain root on kernels…

CVE-2023-51518: Preauthenticated Java Deserialization via JMX in Apache James

PowerShell exploit for PrintNightmare (CVE-2021-1675) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…

Proof-of-concept exploit for CVE-2025-4517, a path traversal vulnerability in Python's tarfile filter='data' sandbox, enabling arbitrary file writes…


Full exploit for needsrestart setuid root shell

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

Technical analysis and proof-of-concept for CVE-2025-6019, a local privilege escalation vulnerability in libblockdev and udisks2, enabling root…

A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.

ADManager Plus Build < 7230 Elevation of Privilege

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

Windows kernel exploit for CVE-2023-21768 that bypasses Driver Signature Enforcement (DSE) to load unsigned drivers, enabling local privilege…

Malicious Payloads that abuses Win32k Elevation of Privilege Vulnerability (CVE-2021-28310)

Exploit for CVE-2018-8120, a Windows local privilege escalation vulnerability, targeting Win7 SP1 x86 and x64 systems.

Python exploit for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) delivering a reverse shell via Netcat listener.

Proof-of-concept exploit for CVE-2020-1472 (ZeroLogon) that changes the domain controller machine account password, enabling DCSync and full domain…