
elfpack
ELF binary section docking toolkit for stageless payload delivery, enabling in-field payload attachment, signature evasion, and static/dynamic…

ELF binary section docking toolkit for stageless payload delivery, enabling in-field payload attachment, signature evasion, and static/dynamic…

Python-based steganography payload generator for macOS that embeds encrypted URLs in innocent files, fetches payloads over HTTPS, and executes them…

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

Exploit for CVE-2023-22515 enabling remote code execution on Confluence servers via custom plugin upload after gaining admin access.

Proof-of-concept exploit for CVE-2022-30190 (Follina) enabling remote code execution via Microsoft Support Diagnostic Tools in Office, with reverse…

Python exploit script for CVE-2015-6967, enabling authenticated arbitrary file upload in Nibbleblog 4.0.3 with custom payload support.

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

Python exploit for CVE-2024-24590 that uploads a malicious pickle file to ClearML, enabling reverse shell or custom command execution on the target…

Proof-of-concept RCE exploit for CVE-2025-55182 targeting Next.js apps. Features interactive shell prompt, batch scanning, custom command execution,…

Python-based exploit tool for CVE-2022-22947 (Spring Cloud Gateway SpEL injection). Supports single-target and batch scanning with custom command…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Graphical exploit tool for CVE-2017-12615 (Tomcat PUT arbitrary file write) with vulnerability detection, command execution, and custom webshell…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an…

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

PoC exploit for CVE-2025-13486, an unauthenticated RCE in the Advanced Custom Fields: Extended WordPress plugin. Verifies vulnerable targets and…

Generate malicious JPEG payloads exploiting ExifTool CVE-2021-22204 for arbitrary code execution, with custom commands or reverse shell support.