
K8tools
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

A unique technique to execute binaries from a password protected zip

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

Proof of concept for exploitation of the vulnerability described in CVE-2025-8220, which concerns the possibility of SQL Injection during the…

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

Exploit for Rocket.Chat 3.12.1 RCE via pre-auth NoSQL injection, leaking admin TOTP secret and password reset token to achieve remote code execution…

Python exploit for CVE-2020-1472 (Zerologon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

Proof-of-concept exploit for unauthenticated remote code execution in SPIP < 4.2.1 via PHP object injection in the password reset form. Provides…

Exploit for CVE-2020-1472 (Zerologon) that resets the domain controller account password, enabling DCSync, with restoration steps to revert changes.

Proof-of-concept exploit for CVE-2020-1472 (ZeroLogon) that changes the domain controller machine account password, enabling DCSync and full domain…

Exploit for CVE-2020-1472 (ZeroLogon) that changes a domain controller's machine account password, enabling DCSync and full domain compromise.…

CVE-2022-22965 poc including reverse-shell support

log4j2 Log4Shell CVE-2021-44228 proof of concept

Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))