
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

A Collection of Over 60 Scripts - updated specifically for the BadUSB function on the FlipperZero.

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Copy Fail - CVE-2026-31431 - Hardened C implementation for redteam and authorized penetration testing operations. ⚠️ Legal Notice: This tool is…

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Filesystem interaction via firebeam virtual machine execution

CVE-2025-31644: Command Injection in Appliance mode in F5 BIG-IP

Exploit PoC for CVE-2023-20198

Modified exploit for CVE-2019-12725 with fixed errors, elevated privilege execution, and removed delays for faster automated exploitation testing.

This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.

CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated…

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

WAGO系统远程代码执行漏洞(CVE-2023-1698)

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…


Proof-of-concept exploit for CVE-2022-36804, a command injection vulnerability in Bitbucket Server and Data Center, enabling arbitrary code execution…