
weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1

XSS payloads designed to turn alert(1) into P1

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

Full-spectrum Linux adversary simulation platform with kernel-level stealth, C2 beaconing, privilege escalation, credential harvesting, lateral…

This script is designed to exploit a heap buffer overflow vulnerability in a socks5 proxy server.

Proof-of-concept exploit for CVE-2022-28219 targeting ManageEngine AuditAD. Ruby-based remote code execution trigger designed for security testing…

Designed for Demonstration of Deep Exploitation.

Proof-of-concept exploit for CVE-2024-2961, demonstrating a remote code execution vulnerability in PHP's iconv function. Designed for security…

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

Python port of a Metasploit exploit targeting CVE-2004-1561 for remote code execution. Designed for penetration testing and vulnerability validation…

Welcome to the Metasploit Exploits Repository, your go-to resource for a comprehensive collection of cutting-edge exploits designed for penetration…

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

This framework is designed to assist penetration testers or developers in understanding the mechanics of remote code execution (RCE) exploitation.

C# implementation of CVE-2017-7269 exploit for Microsoft IIS WebDAV remote code execution. Designed for penetration testing and vulnerability…

A Ruby framework designed to aid in the penetration testing of WordPress systems.

ScareCrow - Payload creation framework designed around EDR bypass.