
TinyLoad
Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

Open source Windows x64 PE packer and crypter. Compresses and encrypts executables with a custom virtual machine into a self extracting stub.

One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

A unique automated LFi Exploiter with Bind/Reverse Shells

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Simple CLI tool for the generation of bind and reverse shells in multiple languages

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

PoC exploit for CVE-2021-33026 that poisons Redis cache in Flask-Cache to achieve remote code execution via malicious pickle deserialization.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Python Based Crypter That Can Bypass Any Kinds Of Antivirus Products

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

Repository to exploit CVE-2023-46604 reported for ActiveMQ