
CVE-2024-6366
Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

CVE-2019-18655 metasploit module. SEH based buffer overflow in file sharing wizard app v.1.5.0.

Metasploit module exploiting CVE-2022-28108 in Selenium Grid for remote code execution, with content-type evasion and post-exploitation capabilities.

generate CobaltStrike's cross-platform payload

NGINX RCE exploits

Hide your Powershell script in plain sight. Bypass all Powershell security features

PE injection technique that overwrites a suspended process's executable with a payload, enabling code execution under a benign process identity.

Abstracts and expedites the process of backdooring stock firmware images for consumer/SOHO routers

PowerShell to Slack C2

Private Nginx Rift ASLR lab, exploit chain, and demo recordings

WordPress Backup Guard Authenticated Remote Code Execution Exploit

Remote Code execution in CentOS web panel

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Metasploit exploit for the CVE-2025-50286.

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

CVE-2022-31491

Studio 3T v.2025.1.0