
Embedded-PDF
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This proof-of-concept script demonstrates how to exploit CVE-2024-4323, a memory corruption vulnerability in Fluent Bit, enabling remote code…

A PoC demonstrating CVE-2025-1913, showing how the plugin’s unsafe unserialize handling can lead to high-impact behavior in controlled environments.…

vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step,…

This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task…

demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Python Remote Administration Tool (RAT)

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

react2shell CVE-2025-55182 PoC