
c-copy-fail
C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

Tips on how to write exploit scripts (faster!)

FastJsonAutoTypeBypass

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).


This is a concept poc of command and control server implemented over blockchain

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

CVE-2020-15368, aka "How to exploit a vulnerable driver"

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…