
StrutsShell
Interactive command-line shell for exploiting Apache Struts CVE-2017-5638. Automates HTTP/HTTPS exploitation with real-time shell interaction on…

Interactive command-line shell for exploiting Apache Struts CVE-2017-5638. Automates HTTP/HTTPS exploitation with real-time shell interaction on…

CVE-2018-10933

CVE-2023-33246:Apache RocketMQ 远程命令执行漏洞检测工具

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

Exploit tool for 1Panel CVE-2025-54424, enabling certificate bypass and remote command execution via WebSocket, with batch scanning and interactive…

A POC for CVE-2019-25065, os command injection in OpenNetAdmin

CVE-2025-54424:1Panel 客户端证书绕过RCE漏洞 一体化工具 (扫描+利用)

Proof-of-concept exploit for CVE-2020-5902, a directory traversal and remote code execution vulnerability in F5 BIG-IP TMUI. Includes file read,…

TinySHell port to SCTP

PyRat,a rat by python xmlrpc

CVE-2019-2725poc汇总 更新绕过CVE-2017-10271补丁POC

Technical write-up and proof-of-concept for CVE-2020-15778, an authenticated command injection vulnerability in OpenSSH scp (<=8.3p1) allowing remote…

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

CVE-2023-20198 Exploit PoC

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Improper Authorization Vulnerability in Confluence Data Center and Server

A third-party Gopher Assassin for the Havoc Framework.

POC for utilizing wikipedia API for Command and Control