
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Python script to inject existing Android applications with a Meterpreter payload.

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

.NET/PowerShell/VBA Offensive Security Obfuscator

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

RCE exploit for dompdf

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE


Exploit Java deserialization vulnerabilities in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS using Python PoC scripts and crafted HTTP requests.

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.