
FastJsonAutoTypeBypass
FastJsonAutoTypeBypass

FastJsonAutoTypeBypass

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

This is a concept poc of command and control server implemented over blockchain

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Windows keylogging module for the Sliver C2 implant framework, using Raw Input to capture keystrokes and expose start, stop, and retrieval commands…

C-based payload for CVE-2022-21894 that maps a second stage payload to call EFI services, extending the original PoC for Secure Boot bypass…

Example payload for CVE-2022-21894

LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)

how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

NCC Group's analysis and exploitation of CVE-2017-8759 along with further refinements