
CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.

I know you are probably here from Hack the Box, if so, yes this one actually works.

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

CVE-2024-56426 Exynos9830 Bootrom Exploit - SM-G985F

Python POC, Exploit for Handlebars.js AST Injection RCE, Handlebars.js versions 4.0.0 through 4.7.8 are affected. CVSS score: 9.8 Critical.

Proof-of-concept exploit for CVE-2025-24813, an unauthenticated RCE in Apache Tomcat via partial PUT and deserialization. Includes Docker lab for…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

Exploit for Pterodactyl Panel ≤ 1.11.10 - unauthenticated LFI to RCE.

PoC for achieving RCE in Langflow versions <1.3.0

BLE exploit framework for Unitree robots: command injection via hardcoded AES keys enables remote takeover, payload injection, and wormable…

Exploit for CVE-2019-18935 (Telerik UI) with WAF bypass via encrypted cookie payload injection and custom memory shell deployment.


RCE exploit for low privileged user via CSRF in open-webui

A BYOSI (Bring-Your-Own-Script-Interpreter) Rapid Payload Deployment Toolkit

Python-based command and control framework with encrypted TLS communication, multiple agent support (Python/C), interactive sessions, file transfer,…

Create fake certs for binaries using windows binaries and the power of bat files

DEFCON 30 Mainframe buffer overlow workshop container

IDPS & SandBox & AntiVirus STEALTH KILLER. MorphAES is the world's first polymorphic shellcode engine, with metamorphic properties and capability to…