
CVE-2019-15107
Python exploit for CVE-2019-15107, an unauthenticated remote code execution vulnerability in Webmin <=1.920 via the password_change.cgi endpoint.

Python exploit for CVE-2019-15107, an unauthenticated remote code execution vulnerability in Webmin <=1.920 via the password_change.cgi endpoint.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Remote BOF Runner is a Havoc extension framework for remote execution of Beacon Object Files (BOFs) using a PIC loader made with Crystal Palace.

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog post as a…

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Removed according to regulations

PoC C&C for the Industroyer malware

CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds

simple c2 written in python to demonstrate security concepts

Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Just simple PoC for the Atlassian Jira exploit. Provides code execution for unauthorised user on a server.

Exploit for CVE-2020-5902 providing remote file read and remote code execution on F5 BIG-IP devices via directory traversal in the TMUI interface.

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

Proof-of-concept exploit for CVE-2020-24572 targeting RaspAP's misconfigured web console to execute arbitrary OS commands and upload files with…

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.