
CVE-2026-73570
Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Proof-of-concept UAC bypass abusing auto-elevated COM objects to copy a user-specified DLL into System32 and trigger a SYSTEM service load for…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Meterpreter auto exploit program

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.

Windows Auto Post Exploitation - For ReD Team

UAC Bypass for windows