
RedbloodC2
Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Open-Source Remote Administration Tool For Windows C# (RAT)

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

FOGProject Authentication bypass CVE-2025-58443 Exploit

Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.