


R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…


Bypass firewall for traffic forwarding using webshell

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

CVE-2026-41940 — cPanel/WHM Auth Bypass By Dr.Anach, CRLF injection in `cpsrvd` Basic auth handler → unauthenticated WHM API access → RCE as root.…

ingress-nginx admission controller RCE escalation PoC

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

OSWE, OSEP, OSED, OSEE

Payload Generation Framework

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.