
ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization

CLI wrapper for CVE-2025-64512 PoC generating malicious PDF and pickle.gz payloads to exploit insecure deserialization in pdfminer.six, enabling…

C# RAT (Remote Administration Tool)

GUI tool for creating malicious RAR archives exploiting CVE-2025-8088 path traversal. Uses NTFS ADS stealth and RAR5 header injection for payload…

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

Exploit for CVE-2025-55182 targeting Next.js React Server Components via prototype pollution, enabling remote code execution with command execution…

CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP…

Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088

A proof-of-concept tool for demonstrating the critical React2Shell vulnerability

Poc for CVE-2025-55182

Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)

CVE-2025-24813-POC JSP Web Shell Uploader

Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

Proof-of-concept exploit for CVE-2024-10586 targeting WordPress Debug Tool plugin. Automates arbitrary file upload leading to remote code execution…

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

CVE-2025-55182 and CVE-2025-66478