
YAPS
Yet Another PHP Shell - The most complete PHP reverse shell

Yet Another PHP Shell - The most complete PHP reverse shell

exploit for CVE-2026-42945

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

ENDGAME C2 FRAMEWORK — AI-powered command and control for professional red team operations


Proof-of-concept exploit for CVE-2022-42889 (Text4Shell) in Apache Commons Text, with manual and mass exploitation scripts using script, URL, and DNS…

Long Range Pager Systems pagers and coasters URH and YS1 (yardstick one / cc11xx) information and brute force tool

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

Proof-of-concept exploit for CVE-2022-44268 enabling arbitrary file read via poisoned PNG images uploaded to vulnerable ImageMagick instances.…

PAKURI-THON is a tool that supports pentesters with various pentesting tools and C4 server (command & control and chat & communication server).…

spring框架RCE漏洞 CVE-2022-22965

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to exploit a system or server that runs a PHP…

Remote Java classpath enumeration via deserialization

A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

a CLI for ephemeral penetration testing

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)