
cve-2026-41940-PoC
Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits pre-auth XSS in WordPress (CVE-2026-64638) to achieve RCE; includes safe-check mode, reverse shell, C2 beaconing, persistence, privilege…

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

Exploit for Apache Kyuubi path traversal (CVE-2026-52680) achieving unauthenticated arbitrary file write and code execution via profile.d shell…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

A chromium extension exploitation toolkit

Exploit for CVE-2026-58057 targeting Flowise Windows RCE via case-sensitive environment variable validation bypass. Supports reverse shell,…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Open-source C2 and proxy for exploiting XSS via malicious Service Workers, enabling persistent browser-based access to target applications as the…

Exploit framework for CVE-2026-6875, a pre-auth RCE in ServiceNow. Chains JS injection, sandbox escape, and root privesc. Includes interactive shell,…

A tool to transform Chromium browsers into a C2 Implant

Proof-of-concept exploit for CVE-2025-52691 (SmarterMail RCE) with APT-level stealth, persistence, file exfiltration, and interactive shell mode for…

Authenticated remote code execution exploit for TP-Link Archer C5 routers via malicious configuration file upload. Injects OS commands with root…

Automated exploitation tool for CVE-2025-55182 (React/Next.js RCE) with command execution, outbound detection, interactive reverse shell, and…

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root