
struts2-tool
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

A simple and efficent script to obfuscate python payloads to make it completely FUD

Proof-of-concept exploit for CVE-2025-55182/66478, a React Server Components deserialization RCE, delivering a reverse shell via crafted multipart…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Exploit chain for unauthenticated RCE on Microsoft SharePoint, combining a JWT authentication bypass with unsafe .NET type instantiation to achieve…

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

CVE-2021-42287/CVE-2021-42278 exploits in powershell

Impacket-based exploit for CVE-2021-1675/34527 (PrintNightmare) enabling remote or local DLL execution on vulnerable Windows systems, with scanning…

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

Exploit script for CVE-2026-34197, targeting Apache ActiveMQ's Jolokia API to achieve remote code execution via malicious Spring XML configuration,…

Proof-of-concept exploit for CVE-2026-23744, targeting /api/mcp/connect to achieve remote command execution on Linux systems via reverse shell.

Proof-of-concept exploit for CVE-2026-21440, enabling file upload and remote command execution on Windows web servers with built-in sensitive path…

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

C# Reflective loader for unmanaged binaries.

Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.