
VMware-CVE-2022-22954-Command-Injector
Python PoC for exploiting VMware CVE-2022-22954 via Freemarker template injection in the catalog-portal UI, enabling remote command execution on…

Python PoC for exploiting VMware CVE-2022-22954 via Freemarker template injection in the catalog-portal UI, enabling remote command execution on…

A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.

Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…

A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with…

Post-exploitation script leveraging .bashrc for persistent payload delivery and terminal manipulation, including destructive display and terminal…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

Python exploit for CVE-2022-36804 command injection in Atlassian Bitbucket Server, enabling remote code execution and reverse shell with customizable…

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.

Generate Caddy redirector configs from Cobalt Strike or Sliver C2 profiles.

Private x64 RCE exploit for CVE-2024-6387 [02.07.2024] from exploit.in

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

A proof of concept demonstrating the use of Google Drive for command and control.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Automated Mass Exploiter

MeterSSH is a way to take shellcode, inject it into memory then tunnel whatever port you want to over SSH to mask any type of communications as a…

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

Red Team engagement platform with the goal of unifying offensive tools behind a simple UI

Generate Payloads and Control Remote Machines. [Discontinued]