CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加设备。
wp2shell - WordPress CVE-2026-63030 Exploit & Scanner
Technical analysis of the cPanel/WHM auth bypass
Use CVE-2026-43499 to disable SELinux on Android
Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1
authz test (CVE-2026-1999 siblings)
Use CVE-2026-43074 to disable SELinux on Android
Pre-auth RCE in WordPress Core via REST API batch route confusion + WP_Query SQLi (CVE-2026-63030 / CVE-2026-60137). Detection PoC.
vivo X Fold6 (V2545A) GhostLock CVE-2026-43499 临时root/永久解锁研究
Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2026-63030, CVE-2026-60137, wp2shell scanner
CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
Academic proof-of-concept demonstrating CVE-2026-46442 for authorized security research.
WordPress KeepInMind CVE-2026-9271 Exploit - Tool detecting stored XSS in KeepInMind plugin v0.8.4.2 and below. Built by Sudeepa Wanigarathna, it simulates CSS injection to hijack admin accounts. Features safe testing, attack simulation, credential capture, bulk scanning, reporting. Essential for security researchers.