
unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

a simple react2shell poc with basic waf bypass

A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).

A simple C-based vulnerability in Webmin versions 1.890 to 1.920

ImaegMagick Code Execution (CVE-2016-3714)

libSSH bypass


CVE-2021-3060

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}.…

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

CVE-2021-26855 proxyLogon metasploit exploit script


CVE-2024-41651

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Generates workable JNDI injection links and deserialization payloads with 80+ gadgets, supporting RMI, LDAP, and HTTP servers for automated…