
CVE-2025-64512
Exploit for CVE-2025-64512 to get a reverse shell.

Exploit for CVE-2025-64512 to get a reverse shell.
Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

A collection of selenium tests that might aid it takeover of a selenium node

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.

Get your data from the resource section manually, with no need for windows apis

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

CVE-2023–4220 Exploit

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

Exploit for Ivanti Automation Manager CVE-2022-44569

LSTAR - CobaltStrike Translated to EN

Python codes of my blog.

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…