
PyIris
PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

POC for CVE-2026-23744 for a python revshell

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

Multiplatform HTTP reverse shell providing a shell-like interface over HTTP, with file upload/download, command history, auto-reconnection, and sudo…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Exploit for Microsoft Exchange Server ProxyLogon (CVE-2021-26855) chained with CVE-2021-27065 to achieve unauthenticated remote code execution and…

An alternative screenshot capability for Cobalt Strike that uses WinAPI and does not perform a fork & run. Screenshot downloaded in memory.

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

PoC Exploit of WordPress Core Unauthenticated RCE known as WP2Shell

Python exploit script for ZoneMinder OS Command Injection (CVE-2023-26039) enabling authenticated remote code execution and reverse shell via the API…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

Graphical RCE exploit tool for CVE-2025-55182 in Next.js RSC. Supports remote command execution, arbitrary JS execution, file read/write, directory…