
liffy
Local file inclusion exploitation tool

Local file inclusion exploitation tool

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Python antivirus evasion tool

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

CVE-2023-34468 - Apache NiFi H2 RCE PoC

Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.

CVE-2026-6279

A remote msfconsole written in Python 2.7 to connect to the msfrcpd server of metasploit. This tool gives you the ability to load modules permanently…

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

Python script to inject existing Android applications with a Meterpreter payload.

Blaze Telegram Backdoor Toolkit is a post-exploitation tool that leverages the infrastructure of Telegram as a C&C


A simple and efficent script to obfuscate python payloads to make it completely FUD

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.