
CVE-2026-5027-Langflow
Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

CobaltStrike BOF to spawn Beacons using DLL Application Directory Hijacking

CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

Powershell-C2

CVE-2024-26229 Beacon Object File version

A Go implementation of PinTheft (CVE-2026-43494)

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2…

JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation…

DLL hijacking to rev shell

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

nim-reverse-shell

Exploit for CVE-2020-1472 (Zerologon) that resets the domain controller account password, enabling DCSync, with restoration steps to revert changes.


Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…