
CVE-2025-64512_PoC
Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Hide your payload into .jpg file

POC for PDF JS' CVE-2024-4367 vuln

CVE discovery

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

LimeSurvey Authenticated RCE

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…

Python script to exploit PlaySMS before 1.4.3

Bootloader unlock (CVE-2022-38694) & root guide for Realme C53 / RMX3760 (Unisoc T612)

Automated exploit for CVE-2012-3153 / CVE-2012-3152

Exploit CVE-2020-29134 - TOTVS Fluig Platform - Path Traversal

This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

Proof-of-concept exploit for CVE-2023-45158, a command injection vulnerability in web2py. Demonstrates remote code execution via crafted HTTP…