
CVE-2026-16723
Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence.…

Static analysis walkthrough of a Metasploit Windows shellcode: PowerShell payload decoding, XOR obfuscation, PEB walking, and Export Address Table…

Exploit source and PoC for CVE-2026-43499 targeting OPPO MT6835 Android device, including preload payload, build scripts, and analysis notes for…

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

Autonomous security operations agent for threat intelligence, vulnerability research, IOC analysis, and red teaming. Supports dual-mode operations…

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

Proof-of-concept exploit for CVE-2025-66478 targeting unsafe React Server Components payload handling in Next.js. Includes automated payload…

Step-by-step lab guide for exploiting CVE-2017-10271 (WebLogic XMLDecoder deserialization RCE) with manual payload construction, blind RCE bypass,…

Python proof-of-concept exploit for CVE-2026-41651, a TOCTOU local privilege escalation in PackageKit allowing unprivileged users to install packages…

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

Educational exploit for CVE-2022-0944 OverlayFS privilege escalation with reverse shell payload delivery and kernel version detection scripts.

Proof-of-concept exploit for CVE-2023-42456, demonstrating privilege escalation via sudo NSS library hijacking through chroot injection. Includes…

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

Exploit for VariaType HTB machine leveraging XML injection in fontTools to achieve RCE via PHP reverse shell payload in .designspace metadata.