
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Python script to inject existing Android applications with a Meterpreter payload.

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

RCE exploit for dompdf

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE



I'll submit the poc after blackhat

CVE-2022-41852 Proof of Concept (unofficial)

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

Exploit code for CVE-2016-9066

fastjson-1.2.58-rce with h2 database

[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization