
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

A collection of useful resources for hacking WordPress and it's plugins and themes

GNU IFUNC is the real culprit behind CVE-2024-3094

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Runtime libc function auditor that detects file access race conditions and symlink vulnerabilities by hooking filesystem syscalls via LD_PRELOAD,…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

Laravel debug mode - Remote Code Execution (RCE)

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.