
novahot
A webshell framework for penetration testers.

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

The SpecterOps project management and reporting engine

The C2 Cloud is a robust web-based C2 framework, designed to simplify the life of penetration testers. It allows easy access to compromised…

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

Step-by-step analysis of CVE-2022-46169: unauthenticated remote code execution in Cacti via authentication bypass and command injection, with Docker…

Repo containing docker-compose files and setup scripts without having to clone the individual reternal components

An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.


CVE-2021-21220 Exploitation infrastructure



Presents how to exploit CVE-2021-44228 vulnerability.

Remote code execution vulnerability in OpenEMR <8.0.0.2.

Log4Shell CVE-2021-44228 Demo

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

Source code minh họa máy chủ c2 demo kịch bản thực thi của CVE-2024-23700