
Graffiti
A tool to generate obfuscated one liners to aid in penetration testing

A tool to generate obfuscated one liners to aid in penetration testing

Mac OS Trojan (RAT) made with love <3

Java-based exploit for CVE-2024-20931 bypassing CVE-2023-21839 patch in Oracle WebLogic. Uses JNDI injection via ForeignOpaqueReference to achieve…

CVE-2026-6307 PoC: Longinus - 2 Boundaries in One Bug https://nebusec.ai/research/v8-cve-2026-6307-writeup/)

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

I know you are probably here from Hack the Box, if so, yes this one actually works.

Strapi Framework Vulnerable to Remote Code Execution

Exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, providing a root shell via a shared library and GCONV_PATH manipulation.

CVE-2025-53547 one of poc code

Proof-of-concept exploit for CVE-2022-1329, a remote code execution vulnerability in WordPress Elementor 3.6.0-3.6.2. Includes Docker-based…

Exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, providing a root shell via a shared library and GCONV path manipulation.

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

Updated PoC for CVE-2025-27410, since the one publicly available in the security advisory is prone to failing.
