#1Tools for creating and customizing malicious code or instructions to execute after exploitation.
Kitploit recommended

Exploit CVE-2020-29134 - TOTVS Fluig Platform - Path Traversal
A CVE-2021-22205 Gitlab RCE POC written in Golang

PoC for CVE-2025-24893

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Lightweight scanner and Nuclei templates for identifying React and Next.js deserialization RCEs (CVE-2025-55182 / CVE-2025-66478).

WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)

This is a basic ROP based exploit for CVE 2020-14871. CVE 2020-14871 is a vulnerability in Sun Solaris systems libpam library, and exploitable over…

Log4Shell Proof of Concept (CVE-2021-44228)

Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell) RCE

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

Open Web Analytics 1.7.3 - Remote Code Execution

Technical analysis and proof-of-concept exploit for CVE-2023-21716, a heap corruption vulnerability in Microsoft Word's RTF font table parser…

CVE-2022-22963 RCE PoC in python

CVE-2018-2628

Generates detection artifacts for CVE-2026-21902 on Juniper Junos Evolved, enabling verification of unauthenticated remote code execution via command…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter