
CVE-2026-64638-PoC-XSS2Shell-
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

基于Java实现的Shellcode加载器

Unauthenticated exploit for CVE-2026-68771, a pickle deserialization RCE in ComfyUI. Plants a crafted shard via /upload/image, triggers it through…

Proof of Concept for exploiting the CVE-2022-22965 (Spring4Shell) vulnerability in an isolated environment, with Remote Code Execution (RCE)…

D/Invoke implementation in Nim


WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.


A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

This repository contains scripts, configurations and deprecated payload loaders for Brute Ratel C4 (https://bruteratel.com/)

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

A shellcode function to encrypt a running process image when sleeping.

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection


Windows x64 handcrafted token stealing kernel-mode shellcode