


Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…




Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

CVE-2022-38532 - Local Privilege Escalation vulnerability in MSI Center Application


The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

proxychains - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or…
