
sliver-gui
A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server…

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

Proof-of-concept exploit for CVE-2025-26633 (MSC EvilTwin) demonstrating remote command execution via malicious .msc files with HTML/ActiveX in…

Exploit script for CVE-2024-50498 code injection in WordPress WP Query Console that checks vulnerability and delivers a reverse shell.

WP Query Console <= 1.0 - Unauthenticated Remote Code Execution

Issabel PBX 4.0.0 Remote Code Execution (Authenticated) - CVE-2024-0986

Takeover of Oracle WebLogic Server

A unified console to perform the "kill chain" stages of attacks.

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

CVE-2021-2109 && Weblogic Server RCE via JNDI

Python-based exploit script for Oracle WebLogic CVE-2020-14882 unauthorized bypass RCE. Tests authentication bypass and remote code execution via…

Proof-of-concept exploit for CVE-2020-14882 in Oracle WebLogic Server, demonstrating remote code execution via crafted HTTP requests to the console…

Struts-RCE CVE-2017-5638