#1Tools for creating and customizing malicious code or instructions to execute after exploitation.
Kitploit recommended

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…
u think that it doesnt but it do

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could…

CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC

Generates .NET deserialization payloads for exploiting insecure deserialization vulnerabilities. Aids penetration testers in validating security…

Automatic script written in python for CVE-2009-3999

PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2021-40444, a Microsoft Office remote code execution vulnerability triggered via malicious ActiveX controls in…

Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

This is a proof of concept for CVE-2023-24610

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

This is an easy to use PoC script to exploit React2Shell-CVE-2025-55182 Nextjs vulnerability. This will help to gain a reverse shell.

A proof of concept exploit script for CVE-2025-55182

CVE-2024-3640绕过Waf进行漏洞利用

Python Script to exploit RCE of CVE-2022-42889