YellowKey free tool for the CVE-2026-45585 BitLocker bypass vulnerability on Windows 10/11. Covered on Tom's Hardware: extract recovery keys, apply remediation, test bypass mitigation and manage BitLocker encryption state. Download YellowKey
Legacy HPE iMC vuln
Tproot es una máquina de nivel Muy Fácil de DockerLabs centrada en la explotación manual del servicio vsftpd 2.3.4 (CVE-2011-2523).
CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)
GitHub Actions workflow sandbox for CVE-2026-45132 reproduction
Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject arbitrary code through MCP stdio. Supports reverse shell, persistence, file upload, credential dumping. For authorized security testing only.
GitHub Actions workflow sandbox (CVE-2026-48546 reproduction)
Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.
CVE-2026-41940 & CVE-2026-41948 — cPanel & WHM Auth Bypass
CVE-2026-43499 exploit configuration for realme RMX3888 (Android 16) - 20 verified kernel offsets
CVE-2026-42533 Nginx
CVE-2021-41773 Apache
Test server and PoC
CVE-2026-64600 - Draft - Check todo
PoC and test server
Metabase CVE-2026-59827 Vulnerability Scanner
Full kill chain for HTB SmartHire: from reconnaissance to root. Covers vhost discovery, MLflow RCE (CVE-2024-37054), bind shell, and privilege escalation using Python module hijacking. A clean writeup for cybersecurity portfolio.
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction