
Indushell
PoC C&C for the Industroyer malware

PoC C&C for the Industroyer malware

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

simple c2 written in python to demonstrate security concepts

Local privilege escalation exploit for CVE-2026-3888 targeting snap-confine and systemd-tmpfiles on Ubuntu, providing SUID and capabilities variants…

The poc for CVE-2022-26809 RCE via RPC will be updated here.

Exploit for Apache Tomcat EncryptInterceptor bypass leading to unauthenticated RCE via Java deserialization on port 4000. Includes lab setup,…

Proof-of-concept exploit for CVE-2022-38374, demonstrating the vulnerability and providing a working exploit for security testing and research.

The offical exploit for Pandora v7.0NG Post-auth Remote Code Execution CVE-2019-20224

Exploit for CVE-2020-5902 providing remote file read and remote code execution on F5 BIG-IP devices via directory traversal in the TMUI interface.

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

The official exploit for Froxlor Remote Code Execution CVE-2023-0315

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

is a tool for creating fake WiFi access points

CVE-2022-40297 - Proof of Concept: Privilege escalation in Ubuntu Touch 16.04 - by PIN Bruteforce

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

Wrapper to maximize ISH iOS app capabilities without jailbreak