
D-RAT_VB.NET_MySQL_PHP
D-RAT [VB.NET]+[MySQL]+[PHP]

D-RAT [VB.NET]+[MySQL]+[PHP]

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader…

Rust crate for ghost-frame call-stack spoofing, runtime indirect syscalls, and APC injection on Windows x64. Provides SSN resolution, JIT stub…

A simple, lightweight Remote Access Tool written in Python

A PoC exploit for CVE-2022-41622 - a CSRF in F5 BIG-IP control plane that leads to remote root

Make CVE-2020-0668 exploit work for version < win10 v1903 and version >= win10 v1903

Source code for SubSeven 2.1.3

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

64-bit Windows kernel privilege escalation exploit for CVE-2016-0040 (WMI Receive Notification vulnerability) using GDI bitmap manipulation for token…

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

CVE-2026-49176 WalletService LPE — standalone PoC + Cobalt Strike BOF (SYSTEM command on interactive session)

CVE-2022-28118

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

RemoteDLLInjector