
flar3ad
POC of CVE-2026-51031 for arbitrary local file read

POC of CVE-2026-51031 for arbitrary local file read

Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

Academic purposes only. Attack against Salesforce lightning with guest privilege.

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts


方便实用的CVE-2026-39363利用工具

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

Exfiltrate data over screen interfaces


Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint…

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…


MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

Content hijacking proof-of-concept using Flash, PDF and Silverlight

PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter