
-CVE-2024-6095
Obfuscated CVE-2024-6095 exploit script that uses random strings, advanced payloads, custom headers, and randomized delays to evade detection during…

Obfuscated CVE-2024-6095 exploit script that uses random strings, advanced payloads, custom headers, and randomized delays to evade detection during…

Penetration testing utility and antivirus assessment tool.

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

A list of useful Powershell scripts with 100% AV bypass (At the time of publication).

generate CobaltStrike's cross-platform payload

Pop shells like a master.

A script written lazily for generating cross-platform backdoors on the go :)

GodOfWar - Malicious Java WAR builder with built-in payloads

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

CVE-2021-22911 Rocket.Chat NoSQL Injection RCE Exploit - Educational Purpose

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.