
CVE-2026-20841
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

Adversary Emulation Framework

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

An all-in-one hacking tool to remotely take over Android devices.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

In-depth reverse engineering analysis of Lumma Stealer, an info-stealer using process hollowing, Native API calls, and C2 communication. Includes…

C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automation.

Go-based exploit development framework with built-in phases for target verification, version scanning, exploitation, and C2. Supports multiple…

The Browser Exploitation Framework Project

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Proof-of-concept exploit for CVE-2026-76060, an OS command injection in ZoneMinder's event export, demonstrating RCE via crafted monitor names.

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Encrypted push-to-talk voice and text communication over Tor hidden services with end-to-end encryption, configurable ciphers, relay mode for group…