
CVE-2025-64495-POC
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

about CVE-2018-14667 from RichFaces Framework 3.3.4

Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.

a open source remote administrator tool

Open Source Implementation of Cobalt Strike's Malleable C2

open source port/reimplementation of the Cobalt Strike BOF Loader as is

Command & Control-Framework created for collaboration in python3

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

This repo contains some Amsi Bypass methods i found on different Blog Posts.

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.

TinySHell port to SCTP


Extending of metasploit-framework

ISF(Industrial Control System Exploitation Framework),a exploitation framework based on Python

Python script for exploiting command injection in Open PLC Webserver v3

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.

Guarded, source-only Humane AI Pin root PoC for CVE-2026-43499