
CVE-2025-53691
Remote code execution (RCE) through insecure deserialization

Remote code execution (RCE) through insecure deserialization

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)

Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Offensive Software Exploitation Course


DEFCON 30 Mainframe buffer overlow workshop container



CVE-2021-44228 POC - Spring / Hibernate

Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive…



JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

macOS Initial Access Payload Generator