
dark-doh
Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Python-based exploit for CVE-2024-10914 targeting command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L NAS devices.

Python exploit for CVE-2022-46196 targeting unauthenticated command injection in Cacti <=1.2.22. Automates version detection and reverse shell…

A version of CVE-2017-0213 that I plan to use with an Empire stager

A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects…

Arbitrary Code Execution on FuguHub 8.4

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)

Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)