
PHP-REVERSE-SHELL
This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Weblogic CVE-2020-14882 unauthorized RCE exploit with patch bypass, command execution, and webshell deployment for penetration testing.

Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service…

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

A python based https remote access trojan for penetration testing

Reverse NTP remote access trojan in python, for penetration testers

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

Exploitation toolkit for CVE-2026-22812 (OpenCode unauthenticated RCE) providing interactive shell, arbitrary command execution, file…

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

Ruby-based proof-of-concept exploit for CVE-2023-2868 command injection in Barracuda ESG, delivering a reverse shell for targeted penetration testing.

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

Automated Java-based exploit tool for CVE-2023-4450 targeting JimuReport, featuring command execution and memory shell injection (Behinder) for…

Security research tool for detecting and testing CVE-2025-63888 (ThinkPHP 5.0.24 File Inclusion RCE vulnerability)

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

Exploit tool for CVE-2022-22947 in Spring Cloud Gateway, featuring vulnerability detection, reverse shell, and outbound connectivity testing.

Python exploit tool for OpenCode RCE (CVE-2026-22812) providing command execution, file read/write/upload/download, and interactive shell for…

Proof-of-concept exploit for CVE-2025-54322, a critical pre-authentication RCE in XSpeeder SXZOS firmware. Provides interactive shell, reverse shell…