
poc-CVE-2026-64638-
PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Generates macOS initial access payloads for Mythic C2: installer packages, Office macros, armed PDFs, disk images, and weaponized PIP/Ruby/NPM…

Exploit for CVE-2017-8759 with HTA payload generation and phishing callback server for remote code execution via crafted Office documents.

Generate C2 payloads embedded in favicon files, executed via PowerShell for covert command-and-control operations.

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

Automated framework for CVE-2023-38831 exploitation with payload generation, email delivery, and download link creation for social engineering…

Proof-of-concept exploit for CVE-2024-25293 demonstrating remote code execution in mjml-app via crafted mj-button href attributes, with a Python…

Proof-of-concept exploit for CVE-2025-1015 demonstrating unsanitized URI fields in Thunderbird Address Book leading to unprivileged JavaScript…

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Proof-of-concept exploit for CVE-2025-0411, demonstrating Mark-of-the-Web bypass in 7-Zip to enable arbitrary code execution via crafted archives…

Proof-of-concept exploit for CVE-2025-22131, an XSS vulnerability in PhpSpreadsheet, demonstrating cookie exfiltration via crafted XLSX files.

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook RCE vulnerability, demonstrating email-based attack with configurable templates and…

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Generates malicious RTF documents exploiting CVE-2017-11882 to execute arbitrary commands or payloads via embedded Equation objects and VBScript.

Scripts for generating Office macro payloads to deliver executables and PowerShell commands, aiding in red team engagements and phishing simulations.

Encrypts and embeds any file into an HTML page with automatic decryption and download simulation for social engineering and payload delivery.

Use a Fake image.jpg to exploit targets (hide known file extensions)