
CVE-2025-47549
Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Automated Proof-of-Concept exploit for CVE-2025-8550, a reflected XSS in atjiu pybbs. Features 20+ payload variations, cookie exfiltration,…

A simple remote tool in C#.

Android Remote Administration Tool

PoC for Windows' IPv6 CVE-2024-38063

🐍 Double Venom (DVenom) is a tool that provides an encryption wrapper and loader for your shellcode.

👁️ (s)AINT is a Spyware Generator for Windows systems written in Java. [Discontinued]

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

DKMC - Dont kill my cat - Malicious payload evasion tool

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

MOGWAI LABS JMX exploitation toolkit

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

Windows - Weaponizing privileged file writes with the Update Session Orchestrator service

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…