
XSS2Shell
Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

A care package of useful bofs for red team engagments

Modern tactical exploitation toolkit.

Notes about attacking Jenkins servers

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

Python codes of my blog.

Intranet penetration tools

CVE-2026-3584

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter

收集网上CVE-2018-0708的poc和exp(目前没有找到exp)

LSTAR - CobaltStrike 综合后渗透插件

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Work in Progress. RAT written in C++ using wxWidgets

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE