
CVE-2021-41773
Exploit scripts for Apache HTTP Server 2.4.49 directory traversal vulnerability (CVE-2021-41773), enabling path traversal and potential RCE via…

Exploit scripts for Apache HTTP Server 2.4.49 directory traversal vulnerability (CVE-2021-41773), enabling path traversal and potential RCE via…

Python exploit for Drupal 8 core RESTful API RCE (CVE-2019-6340) that sends crafted requests to execute arbitrary commands on vulnerable sites.

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

Rejetto http File Server 2.3.x (Reverse shell)

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.

Different methods to get current username without using whoami

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

A browser based visualization of domain trusts. Give it a csv, get a pretty diagram to play with!

CVE-2023-38831 winrar exploit generator and get reverse shell

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Repo that the MS15-011 exploit clones to get required files. Avoids having to download all files from exploit_dev.