
CVE-2026-57588-Nessus-XML-Import-SQL-Injection-PoC
PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

Reverse Shell Detection with Machine Learning

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

CVE-2021-21220 Exploitation infrastructure

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Red Team tool for covert file exfiltration via Bluetooth audio transmission, encoding binary data into FLAC signals to bypass EDR, XDR, and DLP…


Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.

A XXE payload generator

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).


PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…