
poc-CVE-2026-64638-
PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

macOS Initial Access Payload Generator

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

An XSS exploitation command-line interface and payload generator.

PoC for CVE-2025-22131

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Embed and hide any file in an HTML file

JShell - Get a JavaScript shell with XSS.

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.