SlashID fork of conductorone/baton-retool — pgx/v5 port (CVE-2026-32286, CVE-2026-41889); retire when upstream ships pgx/v5
VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)
CVE-2026-31431 Copy Fail PoC and exploit
This is the compiled version. This is not my program though. This is only for directly downloading the compiled version in labs where there is no gcc
CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0 and earlier. The flaw exists in the Express association Reorder dialog, allowing a user with only view permissions on an Express entry to modify the ordering of associations for another entity.
CVE-2026-54121(CertiGhost) without MachineAccountQuota POC
This is N-day patch we releasing by testing our model capabilities
Authenticated Blind OS Command Injection in ClearOS
A Metasploit auxiliary module that escalates from any low-privileged domain user to full domain compromise by abusing the AD CS enrollment "chase" fallback. The CA can be coerced into authenticating back to attacker-controlled infrastructure and then issuing a certificate that impersonates a Domain Controller.
Unprivileged user to root on macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection engineering, threat hunting, incident response, and Kubernetes security implications.
Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.
Exploit for CVE-2020-3952 in vCenter 6.7
CVE-2026-63030 Exploit | by gr1tx
Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 | aimy_captcha-less_form_guard < 20.1
CVE-2022-24903 Heap-based buffer overflow
Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds < 3.11.2
this is a poc for CVE-2026-33937