Fetching description from NVD…
Show 7 repositories
[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
Network Security Project
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live504 results
Fetching description from NVD…
[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
Network Security Project
Fetching description from NVD…
CVE-2019-1388 UAC提权 (nt authority\system)
guest→system(UAC手动提权)
CVE-2019-1388 Abuse UAC Windows Certificate Dialog
CVE-2019-1388 Lab Analysis: Documented local privilege escalation via Windows UAC certificate dialogs on Windows 7.
Fetching description from NVD…
Ubuntu OverlayFS Local Privesc
CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hi…
2021 kernel vulnerability in Ubuntu.
Fetching description from NVD…
exploit for CVE-2022-2588
CVE-2022-2588
CVE-2022-2588,CVE-2022-2586,CVE-2022-2585
CVE-2022-2588,CVE-2022-2586,CVE-2022-2585
SLUBStick exploitation of CVE-2022-2588. Converting a DF into a cross-cache arbitrary memory R/W primitive through PTE manipulation.
CVE-2022-2588
Fetching description from NVD…
Analysis of CVE-2025-43529 (WebKit UAF) + CVE-2025-14174 (ANGLE OOB) exploit chain - iOS Safari
exploit for cve-2025-43529
A demonstration of read write using cve-2025-43529 and userland PAC bypass on iOS 26.1
Root Cause Analysis for CVE-2025-43529, a UAF vulnerability due to incorrect DFG StoreBarrierInsertionPhase in JavaScriptCore.
CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)
webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It induces the …
CVE-2025-43529 Test
Fetching description from NVD…
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068, and CVE-20…
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into safe.txt.
Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning
Fetching description from NVD…
POC code to exploit the Heap overflow in Fortinet's SSLVPN daemon
An exploit for CVE-2022-42475, a pre-authentication heap overflow in Fortinet networking products
CVE-2022-42475 飞塔RCE漏洞 POC
FortiOS buffer overflow vulnerability
test for the ioc described for FG-IR-22-398
Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the S…
Fetching description from NVD…
Proof of concept for CVE-2019-0708
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
Public work for CVE-2019-0708
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
Fetching description from NVD…
Basic vulnerability scanning to see if web servers may be vulnerable to CVE-2023-44487
Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)
Proof of concept for DoS exploit
A python based exploit to test out rapid reset attack (CVE-2023-44487)
Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept
Highly configurable tool to check a server's vulnerability against CVE-2023-44487 by rapidly sending HEADERS and RST_STREAM frames and documenting the server's…
Fetching description from NVD…
Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)
Grafana RCE exploit (CVE-2024-9264)
File Read Proof of Concept for CVE-2024-9264
A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.
Authenticated RCE in Grafana (v11.0) via SQL Expressions - PoC Exploit
Grafana RCE
Fetching description from NVD…
HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras exploiting the W…
command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability t…
海康威视RCE漏洞 批量检测和利用工具
the metasploit script(POC) about CVE-2021-36260
CVE-2021-36260
CVE-2021-36260
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests de…
Identify hikvision ip and probe for cve-s (CVE-2017-7921, CVE-2022-28171, CVE-2021-36260)
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
CVE-2026-9830 Proof of Concept
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of it…
Fetching description from NVD…
POC tool for ResetNightmare (CVE-2026-27912)
CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC
PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security research only.
Fetching description from NVD…
Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including Debian, Ubuntu…
Technical analysis and proof-of-concept for CVE-2024-1086, a Linux kernel nf_tables use-after-free vulnerability leading to local privilege escalation. Include…
HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root
Fetching description from NVD…
CVE-2015-1805 root tool
AndroRAT is a capability that can be used to inject a root exploit as a silent installation to perform a malicious task on the device. This AndroRAT is designe…
HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.
A root tool based on the [CVE-2015-1805 vulnerability](https://access.redhat.com/security/cve/cve-2015-1805) It supports 32 and 64bit, get sys call table addr…
Fetching description from NVD…
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8…
PoC for CVE-2026-3609 - XIGNCODE3 xhunter1.sys handle leak enabling PPL bypass and LSASS dumping
Fetching description from NVD…
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8…
Fetching description from NVD…
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.
Telerik CVE-2017-9248 Vulnerability Scanner
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
Fetching description from NVD…
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traversal, cert…
Fetching description from NVD…
Zimbra - Remote Command Execution (CVE-2024-45519)
Zimbra CVE-2024-45519
Zimbra CVE-2024-45519 real fix - Official patch is incomplete
Fetching description from NVD…
CVE-2019-1040 with Exchange
an impacket-dependent script exploiting CVE-2019-1040
CVE-2019-1040 with Kerberos delegation
Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit
The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration testing.
Fetching description from NVD…
Pure Nim implementation for exploiting CVE-2021-36934, the SeriousSAM local privilege escalation
PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version 1809 or newer
Fix for the CVE-2021-36934
HiveNightmare a.k.a. SeriousSam Local Privilege Escalation in Windows – CVE-2021-36934
Small and dirty PoC for CVE-2021-36934
PoC for CVE-2021-36934 Aka HiveNightmare/SeriousSAM written in python3
HiveNightmare aka SeriousSAM
Detection and Mitigation script for CVE-2021-36934 (HiveNightmare aka. SeriousSam)
Fetching description from NVD…
Original PoC for CVE-2023-32784
KeePass 2.X dumper (CVE-2023-32784)
This script complements the results obtained through the keepass-password-dumper tool when exploiting the CVE-2023-32784 vulnerability affecting KeePass.
KeePass Master Password Extraction PoC for Linux
Re-write of original KeePass 2.X Master Password Dumper (CVE-2023-32784) POC in python.
Retrieve the master password of a keepass database <= 2.53.1
year 2 semester 1 Systems and Network Programming Assignment
Fetching description from NVD…
Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
CVE-2024-20931, this is the bypass of the patch of CVE-2023-21839
CVE-2023-21839工具
CVE-2023-21839 Python版本
Reproducible Docker lab for CVE-2024-21182 — Oracle WebLogic T3/IIOP OpaqueReference JNDI injection → unauthenticated RCE (CVE-2023-21839 patch-bypass family).…
A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432
Fetching description from NVD…
CVE-2023-0386在ubuntu22.04上的提权
CVE-2023-0386 analysis and Exp
Vulnerabilities Exploitation On Ubuntu 22.04
非常简单的CVE-2023-0386's exp and analysis.Use c and sh.
CVE-2023-0386 EXP
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.