
Tools for creating and customizing malicious code or instructions to execute after exploitation.

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…


CLI wrapper for CVE-2025-64512 PoC generating malicious PDF and pickle.gz payloads to exploit insecure deserialization in pdfminer.six, enabling…

Pix for WooCommerce Unauthenticated File Upload via certificate_crt_path Parameter | CVSS 9.8

Nim touch up of CVE 2024 26229

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.

A PoC script for CVE-2026-38526, RCE via a file upload vulnerability in the /admin/tinymce/upload endpoint of webkul krayin 2.2.x

CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to…

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full…

CVE-2026-63030 - WordPress Core Pre-Auth RCE Mass Exploit

Pre-auth RCE PoC for CVE-2026-63030 / CVE-2026-60137 (WordPress core)

PoC Exploit of WordPress Core Unauthenticated RCE known as WP2Shell

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

CVE-2026-38526 Exploit | by infrar3d