# 0days Vault

> **Author:** YogSotho - BrokenSec

Private exploit-development vault. **211 archives** — all downloads are auth-gated; index browsing is public.

## Contents

### Fortinet / Forti* family  (26 archives, 612K)

| Archive | Size |
|---|---|
| `CVE-2024-21762-FortiOS-SSLVPN-RCE-exploit-kit.zip` | 24K |
| `CVE-2024-21762-FortiOS.zip` | 23K |
| `CVE-2024-23108-FortiSIEM-exploit-kit.zip` | 18K |
| `CVE-2024-23108-FortiSIEM.zip` | 17K |
| `CVE-2024-47575-FortiManager-FortiJump-exploit-kit.zip` | 28K |
| `CVE-2024-47575-FortiManager.zip` | 27K |
| `CVE-2025-25256-FortiSIEM-exploit-kit.zip` | 19K |
| `CVE-2025-25256-FortiSIEM.zip` | 18K |
| `CVE-2025-25257-FortiWeb-SQLi-RCE-exploit-kit.zip` | 21K |
| `CVE-2025-25257-FortiWeb.zip` | 20K |
| `CVE-2025-32756-Fortinet-exploit-kit.zip` | 21K |
| `CVE-2025-32756-Fortinet.zip` | 20K |
| `CVE-2025-59718-FortiOS-SAML-bypass-exploit-kit.zip` | 19K |
| `CVE-2025-59718-FortiOS.zip` | 18K |
| `CVE-2025-64446-FortiWeb-AuthBypass-exploit-kit.zip` | 21K |
| `CVE-2025-64446-FortiWeb.zip` | 20K |
| `CVE-2026-24018-FortiClientLinux-LPE-exploit-kit.zip` | 25K |
| `CVE-2026-24018-FortiClientLinux.zip` | 24K |
| `CVE-2026-25089-FortiSandbox-exploit-kit.zip` | 18K |
| `CVE-2026-25089-FortiSandbox.zip` | 17K |
| `CVE-2026-35616-FortiClientEMS-exploit-kit.zip` | 30K |
| `CVE-2026-35616-FortiClientEMS.zip` | 28K |
| `CVE-2026-39808-FortiSandbox-exploit-kit.zip` | 17K |
| `CVE-2026-39808-FortiSandbox.zip` | 16K |
| `CVE-2026-70465-Fortinet-exploit-kit.zip` | 53K |
| `CVE-2026-70465-Fortinet.zip` | 51K |

### New additions — verified present (14 kits, 1.2M)

| Archive | What's inside |
|---|---|
| `cve-2026-12940-exploit-kit.zip` | CVE-2026-12940 Langflow OSS unauth RCE (LD_PRELOAD / SHELLOPTS vectors) |
| `unifi-sab064-exploit.zip` | UniFi OS SAB-064 framework (5 CVEs: auth bypass, traversal, 2x command injection) |
| `iot-go-expl.zip` | IoT command-injection hunters (DAKboard / Netis / Grandstream) — Go |
| `centrestack_cve_framework.zip` | CentreStack 5-CVE framework (token forgery, session injection, XXE, deserialization) |
| `cve-2026-56290-exploit-kit.zip` | Joomla Page Builder CK (CVE-2026-56290) kit |
| `ios-darksword-coruna-framework.zip` | DarkSword x CORUNA iOS 18.4-18.7 full-chain (JIT→kernel→root) |
| `netscale-pwner.zip` | NetScaler/Citrix ADC multi-CVE framework (2026 bulletins + ColdFusion set) |
| `Fortinet-Hunter-framework.zip` | Fortinet Hunter 2026 — 27-CVE mapper, fuzzing, FortiCrack, C2/exfil |
| `jb_gen_v5.0.zip` | JB-Gen v5.0 — LLM jailbreak generator (GCG suffix, PAIR, genetic evolution) |
| `CVE-2026-38526-krayin-quickkit.zip` | Krayin CMS quick-kit (scanner + exploit) |
| `CVE-2026-38526-krayin-GodTier.zip` | Krayin CMS full framework (TinyMCE upload → webshell → RCE, auth/fingerprint/upload tests) |
| `apple-certificate-hunter.zip` | Apple Enterprise Certificate Hunter v5.3 (multi-source + CT + keyless) |
| `geo-port-expl.zip` | GeoServer GeoTools SQLi → PostgreSQL RCE + test suite |
| `fortios-config-decrypt.zip` | FortiOS 7.0.0 config ENC decryption framework |
| `cl4r1t4s-liberator.zip` | Cl4r1t4s Liberator — PromptEvolver jailbreak generator |

### Second merge — Celestia / vuln-lab / proxy (6 archives, 330K)

| Archive | What's inside |
|---|---|
| `celestia-jwt-scanner.zip` | JWTCelestia — 15-module JWT scanner (alg:none, RS/ES confusion, KID/JWK/JKU/X5U/X5C, psychic sig ECDSA, timing) |
| `sx6632yf-exploit-kit.zip` | TP-Link SX6632YF kit — 5 CVEs, RCE + firmware implant + persistence |
| `archer-be900-exploit-kit.zip` | TP-Link Archer BE900 v2 — dnsmasq/uhttpd/cloud-https/proftpd 4-vector kit |
| `be900-0day-live-verified.zip` | BE900 live-verified PoCs — TDDP/Tether results re-scoped post-QEMU |
| `xenforo-2.3.10-exploit-chain.zip` | XenForo chain — stored XSS CVE-2026-35057 → cookie theft → template RCE CVE-2024-38458 |
| `proxy-suite.zip` | Proxy infra — ip-finder 2.0–5.0, checker, tcp relay, NetNut extractor, pcurl v2.1, god-tier validator |

### Third merge — ghostlock / TPC worm / weblock / Zyxel-TP-Link (4 archives, 233K)

| Archive | What's inside |
|---|---|
| `ghostlock-cve-2026-43499.zip` | GhostLock — Linux kernel futex PI rt_mutex stack-UAF (CVE-2026-43499) LPE + container escape, ARM32/x86, 97% reliable |
| `tpc-worm-framework.zip` | TPC Worm — autonomous cloud-native propagation (etcd/kube/ray/kubelet/redis/mq/cloud-meta/docker-escape/persistence) |
| `weblock-cve-2026-60206.zip` | WebLogic SAML 2.0 auth bypass (CVE-2026-60206) — unsigned-assertion + XSW comment/replay, scanner + QEMU lab |
| `zyxel-tplink-elite-exploits.zip` | Zyxel UPnP cmd-inj (CVE-2025-13942) + Tapo C200 (CVE-2021-4045) + Archer AX50 (CVE-2025-40634) unified framework |
| `multi-cve-exploit-kit.zip` | 40-CVE standalone Oracle Fusion/EBiz + SharePoint weaponized scripts (common.py transport, 66 tests) |

> **centrestack_cve_framework.zip updated** → now covers 6 CVEs (added CVE-2026-54368 SQLi via x-glad-filter → lo_export RCE).

### Fourth merge — EDR-killer / Hitachi / Gitea / Shai-Hulud / CoinHJ (6 archives)

| Archive | What's inside |
|---|---|
| `edr-killer-2026-edition.zip` | BYOVD EDR disabler (Silent Horizon) — 4 vulnerable drivers, 10+ EDR targets, kernel callbacks + ETW + IRP patching |
| `cve-2025-2902-hitachi-vsp.zip` | Hitachi VSP CVE-2025-2902 maintenance-utility auth bypass → RCE |
| `cve-2026-58443-gitea-authbypass.zip` | Gitea public-only token PR-update auth bypass (CVE-2026-58443, CVSS 9.1) |
| `cve-2026-60004-gitea-rce.zip` | Gitea diffpatch Git-hook RCE (CVE-2026-60004, CVSS 9.8) |
| `shai-hulud-re-analysis.zip` | Shai-Hulud dropper deobfuscation toolchain + 10 decrypted payloads + Ethereum C2 resolver |
| `coinhj-clipboard-hijacker-re.zip` | CoinHJ clipboard hijacker RE + C++ source reconstruction + AutoIt source |

> **ghidra-rce.zip enhanced** — added BrokenSec brokensec exploit/scanner/test + CVE-2026-brokensec doc + scan-report.

### Seventh merge — check_me (round 2) (3 archives)

| Archive | What's inside |
|---|---|
| `cve-2026-35057-xenforo-xss.zip` | CVE-2026-35057 XenForo 2.3.10 stored XSS (structured mentions) + weaponized chain (ruff 0) |
| `xenforo-2.3.10-infoleak-chain.zip` | XenForo 2.3.10 22-vuln recon/info-leak chain (debug-mode leak, host-header, user-enum, SSRF; fixed 7× global-before-declaration SyntaxErrors) |
| `ios-stealer-darksword.zip` | iOS 17–18 infostealer JS modules (keychain, icloud, wallets, wifi, credential harvest) for DarkSword chain |

### Sixth merge — check_me (6 archives)

| Archive | What's inside |
|---|---|
| `cve-2026-54121-certighost-toolkit-pro.zip` | CVE-2026-54121 CertiGhost AD CS toolkit PRO (6 Python tools, audited ruff 0) |
| `cve-2026-61511-vbulletin-toolkit.zip` | CVE-2026-61511 vBulletin exploit + scanner (audited ruff 0) |
| `cve-2026-46817-oracle-ebs.zip` | CVE-2026-46817 Oracle EBS Payments RCE kit (full pkg: src+tests+dist, ruff 0) |
| `stealth-keylogger-main.zip` | Stealth Windows keylogger (C++, indirect syscalls + API hashing) |
| `veneficus-mini-v3.zip` | Veneficus Mini v3.0 Rust implant framework (BYOVD, DKOM, HVNC, C2 relay) |
| `kernel-and-daemon-pocs.zip` | C PoCs: CVE-2026-23416 (kernel), CVE-2026-31429 (slab), CVE-2026-27831 (rldns DoS) + RCE YAML rule |

### Fifth merge — new_exploits (22 archives)

| Archive | What's inside |
|---|---|
| `cve-2025-50165.zip` | CVE-2025-50165 research notes |
| `cve-2026-10702-ionstack-android.zip` | CVE-2026-10702 IonStack Android kernel |
| `cve-2026-13019-arcgis.zip` | CVE-2026-13019 ArcGIS Server RCE |
| `cve-2026-44963-apache-log4j.zip` | CVE-2026-44963 Apache Log4j RCE |
| `cve-2026-48939-joomla-icagenda.zip` | CVE-2026-48939 Joomla iCagenda RCE |
| `cve-2026-52813-gogs.zip` | CVE-2026-52813/52806 Gogs |
| `cve-2026-57149-plone.zip` | CVE-2026-57149 Plone RCE |
| `cve-2026-58455-dockwatch.zip` | CVE-2026-58455 DockWatch RCE |
| `cve-2026-6307-v8.zip` | CVE-2026-6307 V8 exploit (JS + Python kit) |
| `misc-exploits-collection.zip` | Misc Go+Python exploit scripts |
| `BlueHammer-main.zip` | BlueHammer |
| `RoguePlanet-main.zip` | RoguePlanet |
| `avtech-elite-toolkit.zip` | Avtech elite toolkit |
| `geovision-kraken-toolkit.zip` | GeoVision Kraken toolkit |
| `cve202641096_windows_dns_exploit_kit(1).zip` | Windows DNS CVE-2026-41096 |
| `neterbit_nw431f_cve202569755_exploit_kit(1).zip` | Neterbit NW431F CVE-2025-69755 |
| `panos_globalprotect_cve20260257_exploit_kit(1).zip` | PAN-OS GlobalProtect CVE-2026-0257 |
| `tenda_hg7hg9_multi_cve_exploit_kit.zip` | Tenda HG7/HG9 multi-CVE |
| `hajime-enhanced-v2.0.zip` | Hajime worm enhanced v2.0 |
| `safeheron-gg20-exploit-toolkit.zip` | SafeHeron GG20 MPC exploit |
| `massload.zip` | massload Go massloader |
| `telnet.zip` | telnet HTTPDoS + brute toolkit |
| `manji-botnet.zip` | Manji (Mirai variant) C bot |
| `research-notes-and-misc.zip` | HackerOne notes, CRO bypass, SafeHeron PDF, Next.js RCE v2/v3 |

### CVE exploit kits  (46 archives, 1M)

| Archive | Size |
|---|---|
| `CVE-2025-56399-backup.zip` | 14K |
| `CVE-2025-56399.zip` | 14K |
| `CVE-2026-10187-exploit-framework.zip` | 19K |
| `CVE-2026-10187.zip` | 5K |
| `CVE-2026-10187_Totolink N300RH.zip` | 5K |
| `CVE-2026-11417-Exploit-Kit.zip` | 80K |
| `CVE-2026-12174-Exploit-Kit.zip` | 54K |
| `CVE-2026-12569-exploit-kit-backup.zip` | 14K |
| `CVE-2026-12569-exploit-kit.zip` | 14K |
| `CVE-2026-35018.zip` | 16K |
| `CVE-2026-35273.zip` | 29K |
| `CVE-2026-35273_Oracle PeopleSoft Environment.zip` | 28K |
| `CVE-2026-38526-krayin-GodTier.zip` | 40K |
| `CVE-2026-41940-2.py.zip` | 3K |
| `CVE-2026-41940.py.zip` | 13K |
| `CVE-2026-47294-sharepoint-exploit-kit.zip` | 22K |
| `CVE-2026-48519.zip` | 19K |
| `CVE-2026-50751-Exploit-Kit.zip` | 34K |
| `CVE-2026-9151-Kit.zip` | 65K |
| `CVE-2026-9151_tplink_archer_exploit_kit.zip` | 3K |
| `CVE_2021_3129_Laravell_ignition.zip` | 12K |
| `CVE_2026_24061_telnet_new-environ.zip` | 15K |
| `CVE_2026_32746_telnetd_LINEMODE_SLC.zip` | 14K |
| `CVE_2026_34159_llamacpp_RCP.zip` | 18K |
| `CVE_2026_34197_activemq-jolokia.zip` | 17K |
| `CVE_2026_34486_apache_tomcat.tribes.zip` | 15K |
| `CVE_2026_41940_cPanel_WHM.zip` | 17K |
| `CVE_2026_42782_apache_syncope.zip` | 8K |
| `CVE_2026_42945_nginx-rift.zip` | 16K |
| `CVE_2026_55182_React2Shell.zip` | 17K |
| `cve-2025-55182-exploit-kit.zip` | 10K |
| `cve-2025-55182-godtier.zip` | 15K |
| `cve-2025-67038-exploit-kit.zip` | 10K |
| `cve-2026-10561-exploit-kit.zip` | 11K |
| `cve-2026-10643-exploit-kit.zip` | 13K |
| `cve-2026-12174-exploit-kit.zip` | 150K |
| `cve-2026-12814-exploit-kit.zip` | 8K |
| `cve-2026-4767-exploit-kit.zip` | 11K |
| `cve-2026-50242-exploit-kit.zip` | 16K |
| `cve-2026-5366-prefect-exploit-kit.zip` | 1K |
| `cve-2026-55200-exploit-kit.zip` | 15K |
| `cve-2026-7840-exploit-kit.zip` | 10K |
| `cve-2026-8451-exploit-kit.zip` | 18K |
| `cve_2026_12174.zip` | 58K |
| `cve_2026_22769_kit.zip` | 26K |
| `cve_2026_48558_kit.zip` | 83K |

### Edimax / Totolink  (6 archives, 55K)

| Archive | Size |
|---|---|
| `CVE_2026_9439_edimax.zip` | 5K |
| `CVE_2026_9440_edimax.zip` | 5K |
| `CVE_2026_9441_edimax.zip` | 7K |
| `CVE_2026_9442_edimax.zip` | 9K |
| `CVE_2026_9443_edimax.zip` | 15K |
| `CVE_2026_9455_a8000ru-setdmzcfg.zip` | 12K |

### Genesis World  (3 archives, 81K)

| Archive | Size |
|---|---|
| `genesis-world-cache-poisoning.zip` | 29K |
| `genesis-world-poison-kit-v1.0.zip` | 30K |
| `genocide-Genesis-World-Poison-ExploitKit-V1.0.zip` | 22K |

### Upgraded toolkits  (29 archives, 351K)

| Archive | Size |
|---|---|
| `cisco-sdwan-elite-toolkit.zip` | 12K |
| `cisco_20230_upgraded.zip` | 15K |
| `dlink-dir823x-elite-toolkit.zip` | 11K |
| `elite-enhanced-cves-toolkit.zip` | 12K |
| `fortisandbox_upgraded_exploit_kit.zip` | 12K |
| `ivanti_sentry_upgraded_exploit_kit.zip` | 18K |
| `joomla_upgraded_exploit_kit.zip` | 12K |
| `koa-router-bypass-exploit-toolkit.zip` | 6K |
| `langflow_multi_cve.zip` | 15K |
| `netlogon_upgraded_exploit_kit.zip` | 13K |
| `panos_upgraded_exploit_kit.zip` | 14K |
| `predator_w6x_upgraded.zip` | 14K |
| `quantum-networks-dual-rce-toolkit.zip` | 12K |
| `safeheron-gg20-exploit-toolkit.zip` | 21K |
| `samba-rce-exploit-toolkit.zip` | 6K |
| `splunk_20253_upgraded.zip` | 16K |
| `tbk-dvr-toolkit.zip` | 9K |
| `tenda_cx12l_multi_cve_exploit_kit.zip` | 2K |
| `tenda_cx12l_upgraded.zip` | 15K |
| `tenda_f451_multi_cve_exploit_kit.zip` | 3K |
| `tenda_f451_upgraded.zip` | 14K |
| `tenda_hg7hg9_upgraded_toolkit.zip` | 14K |
| `totolink-a8000ru-setadvancedinfoshow-toolkit.zip` | 10K |
| `totolink-a8000ru-setstoragecfg-toolkit.zip` | 10K |
| `totolink-a8000ru-setsyslogcfg-toolkit.zip` | 10K |
| `tplink-zte-toolkit.zip` | 8K |
| `tplink_archer_20269151_upgraded.zip` | 14K |
| `tplink_upgraded_exploit_kit.zip` | 14K |
| `winsdns_upgraded_exploit_kit.zip` | 18K |

### Other  (39 archives, 19M)

| Archive | Size |
|---|---|
| `Cosmic.zip` | 571K |
| `GreatXML-main.zip` | 84K |
| `PREDATOR-W6x-MULTI.zip` | 9K |
| `RoguePlanet-main.zip` | 260K |
| `Shai-Hulud-Open-Source-main.zip` | 142K |
| `ac1200_exploit.go.zip` | 2K |
| `acer-wave7-exploit-kit.zip` | 13K |
| `adb_scanner.go.zip` | 5K |
| `all-readmes-updated.zip` | 108K |
| `botnet.zip` | 14M |
| `cPanel-WHM-AuthBypass-to-RCE.py.zip` | 3K |
| `cf-exploit-kit.zip` | 35K |
| `check_2026-41940.py.zip` | 3K |
| `citrix-pwnage-6.6.6.zip` | 32K |
| `claude-code-awk-bypass-labtested.zip` | 31K |
| `claude-code-awk-bypass.zip` | 9K |
| `cpanelsniper.py.zip` | 12K |
| `cve-50521-exploit-kit.zip` | 26K |
| `cve202620230_exploit_kit.zip` | 2K |
| `django-v6-cache-poisoning.zip` | 14K |
| `dlink-dcs935l-cve.zip` | 44K |
| `edge-uaf-exploit-kit.zip` | 8K |
| `edimax-br6478ac-exploit-framework.zip` | 13K |
| `ghidra-rce.zip` | 28K |
| `hermes-agent-multi-exploit-kit.zip` | 20K |
| `ios-darksword-chain.zip` | 36K |
| `ios_security_assessment_platform.zip` | 49K |
| `kestra-exploit-kit.zip` | 11K |
| `kmw-cctv-cve-2026-5386.zip` | 13K |
| `lerobot-exploit-kit.zip` | 10K |
| `manji-FULLY-FIXED-COMPLETE.zip` | 153K |
| `next-js-rce.py.zip` | 2K |
| `nginx-rift.zip` | 16K |
| `predator_w6x_exploit_kit(1).zip` | 3K |
| `tplink_archer_cve20269151_exploit_kit.zip` | 3K |
| `utt_hiper_kit.zip` | 40K |
| `v8-cve-2026-6307.zip` | 11K |
| `waterfall-wf500-cve-2025-exploit-framework.zip` | 19K |
| `x86springboard.zip` | 4M |

---

Access: `https://gibliz.taile5d4a8.ts.net/0days/` — browse freely; downloads require credentials.
