
XSS2Shell
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)
Tools for creating and customizing malicious code or instructions to execute after exploitation.

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

CVE-2026-64638 - Draft or TODO



PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).


CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…






Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

Multi-platform Python webshell providing remote shell access on web servers with command history, file upload/download, and directory traversal…
