
ARES
Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…

Autonomous red-team engagement platform with MITRE ATT&CK module orchestration, DAG attack-path solving, OPSEC controls, encrypted credential vault,…

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

Proof-of-concept exploit for CVE-2026-26114, a remote code execution vulnerability in Microsoft SharePoint, with a Python PoC and Metasploit module…

Authenticated remote code execution exploit for Webmin < 1.997 via the Software Package Updates module. Injects arbitrary commands as root through an…

POC for CVE-2025-24054

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

Adaptix C2 agent using Crystal Palace PIC linker and PICO module system

CVE-2022-31491

Remote privilege escalation exploit for CVE-2018-1049 targeting VyOS via SSH-based command injection in a sudo-permitted Perl script, granting root…

PoC for generating bthprops.cpl module designed to be loaded by Fsquirt.exe LOLBin

CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.

CVE-2023-30990 exploits

Remote Code execution in CentOS web panel

CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework

Python exploit for CVE-2007-2447 targeting Samba smbd 3.0.20-Debian with reverse shell payload delivery via Netcat listener.

IP obfuscator made to make a malicious ip a bit cuter

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.