
libextractor-privesc
Proof-of-concept for CVE-2026-100310, a local privilege escalation in GNU libextractor ≤1.15 via the LIBEXTRACTOR_PREFIX untrusted search path, with…

Proof-of-concept for CVE-2026-100310, a local privilege escalation in GNU libextractor ≤1.15 via the LIBEXTRACTOR_PREFIX untrusted search path, with…

Exploit Windows server 2019 vulnerable to Zerologon with Garble, Chisel, wp-file-manager vulnerability (have video demo)

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

Proof-of-concept exploit for CVE-2025-1562, a WordPress plugin activation vulnerability allowing remote code execution via crafted REST API requests.

Explore CVE-2022-41741 with the Evil MP4 repository. It offers educational PoCs,and documentation on securing nginx against MP4 file vulnerabilities.…

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)


Python exploit for Moodle Evil Teacher vulnerability (CVE-2018-1133) enabling authenticated remote command execution with proxy support.

CVE-2023-38831 winrar exploit generator

Python-based exploit generator for CVE-2023-38831 (WinRAR remote code execution). Creates malicious RAR archives with bait files and payload scripts…

Python-based exploit generator for CVE-2023-38831 WinRAR vulnerability. Creates malicious RAR archives with bait files (PDF, images) and payload…

Automated exploit script combining CVE-2020-1472 (ZeroLogon) with evil-winrm to gain a remote shell on vulnerable Windows Domain Controllers.

CVE-2019-5010 Exploit PoC - Python Denial of Service via Malformed X.509v3 Extension

Don't be evil.

Proof of Concept for CVE-2021-1585: Cisco ASA Device Manager RCE

Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)

An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228

Kernel-level iptables backdoor that accepts all packets with the RFC 3514 evil bit set, bypassing firewall rules. Includes in-tree and out-of-tree…