
CVE-2021-24155.rb
WordPress Backup Guard Authenticated Remote Code Execution Exploit

WordPress Backup Guard Authenticated Remote Code Execution Exploit

Emulates open ports and service signatures across all 65535 TCP ports to slow reconnaissance, confuse scanners, and waste attacker resources with…

This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting…

This repository contains a PoC for exploiting CVE-2024-32002, a vulnerability in Git that allows RCE during a git clone operation. By crafting…



POC for CVE-2026-49009, an authenticated path traversal to RCE issue in Mender Server.

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

A POC C2 server and agent to explore just if/how the Ethereum blockchain can be used for C2

Automated Linux evil maid attack

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files


An exploitation demo of Outlook Elevation of Privilege Vulnerability

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

Streaming Unexpected Network Byte Sequences with High Probability of Blue Screening or Otherwise Crashing Attacker Command-and-Control Nodes

An issue was discovered on TP-Link TL-WR840N. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…