
Pokemon-Shellcode-Loader
Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

Tired of looking at hex all day and popping '\x41's? Rather look at Lugia/Charmander? I have the solution for you.

IronSharpPack is a repo of popular C# projects that have been embedded into IronPython scripts that execute an AMSI bypass and then reflective load…

CVE discovery

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

POC for CVE-2023-38646

Apache Log4j 远程代码执行

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…

An unauthenticated PoC for CVE-2020-0796

Golang exploit for CVE-2017-5638

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

Automated exploit wrapper for MS09-050 (CVE-2009-3103) targeting SMBv2 on Windows Vista/Server 2008. Generates shellcode, builds exploit, and creates…

CVE-2023-5180 LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1