
vulmap
Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Python exploit script for CVE-2020-28458, a prototype pollution vulnerability in DataTables. It sends crafted payloads to target URLs, supports proxy…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Acunetix 0day RCE

Automatic SSTI detection tool with interactive interface

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

A PoC Java Stager which can download, compile, and execute a Java file in memory.

GNU IFUNC is the real culprit behind CVE-2024-3094

A collection of useful resources for hacking WordPress and it's plugins and themes

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

ExportHider: Generating Export Table during Runtime to Hide the Exported Functions from the DLL File.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

Laravel debug mode - Remote Code Execution (RCE)