
rcekit
RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Reproduces the CVE-2026-70638 integer overflow in llama.cpp Android JNI with a safe arithmetic demo, malicious GGUF generator, and Frida hook for…

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A collaborative web exploitation framework.

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Universal stack-based buffer overfow exploitation tool

Burp Suite extension to generate Intruder payloads using Radamsa

CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Generic Scanner for Apache log4j RCE CVE-2021-44228

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

Laboratorio para el análisis y explotación del CVE-2025-5548

Apache OfBiz vulns

Proof of concept with the academic purpose to understand the Buffer Overflow vulnerability using as background the CVE-2019-11395
